Vulnerabilities > CVE-2007-2290 - Unspecified vulnerability in Cafelog B2 0.6.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN cafelog
exploit available
Summary
Multiple PHP remote file inclusion vulnerabilities in B2 Weblog and News Publishing Tool 0.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the b2inc parameter to (1) b2archives.php, (2) b2categories.php, or (3) b2mail.php. NOTE: this may overlap CVE-2002-1466.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description CafeLog B2 0.6.1 Weblog and News Publishing Tool b2categories.php b2inc Parameter Remote File Inclusion. CVE-2007-2290. Webapps exploit for php platform id EDB-ID:29905 last seen 2016-02-03 modified 2006-04-25 published 2006-04-25 reporter alijsb source https://www.exploit-db.com/download/29905/ title CafeLog B2 0.6.1 Weblog and News Publishing Tool b2categories.php b2inc Parameter Remote File Inclusion description CafeLog B2 0.6.1 Weblog and News Publishing Tool b2archives.php b2inc Parameter Remote File Inclusion. CVE-2007-2290. Webapps exploit for php platform id EDB-ID:29904 last seen 2016-02-03 modified 2006-04-25 published 2006-04-25 reporter alijsb source https://www.exploit-db.com/download/29904/ title CafeLog B2 0.6.1 Weblog and News Publishing Tool b2archives.php b2inc Parameter Remote File Inclusion description CafeLog B2 0.6.1 Weblog and News Publishing Tool b2mail.php b2inc Parameter Remote File Inclusion. CVE-2007-2290. Webapps exploit for php platform id EDB-ID:29906 last seen 2016-02-03 modified 2006-04-25 published 2006-04-25 reporter alijsb source https://www.exploit-db.com/download/29906/ title CafeLog B2 0.6.1 Weblog and News Publishing Tool b2mail.php b2inc Parameter Remote File Inclusion
References
- http://osvdb.org/35550
- http://osvdb.org/35550
- http://osvdb.org/35551
- http://osvdb.org/35551
- http://osvdb.org/35552
- http://osvdb.org/35552
- http://securityreason.com/securityalert/2632
- http://securityreason.com/securityalert/2632
- http://www.securityfocus.com/archive/1/466860/100/0/threaded
- http://www.securityfocus.com/archive/1/466860/100/0/threaded
- http://www.securityfocus.com/bid/23659
- http://www.securityfocus.com/bid/23659
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33884
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33884