Vulnerabilities > CVE-2007-2347 - Remote File Include vulnerability in Sisplet CMS Komentar.PHP

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
oneclick-cms
sisplet-cms
exploit available

Summary

PHP remote file inclusion vulnerability in main/forum/komentar.php in OneClick CMS (aka Sisplet CMS) 05.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter.

Vulnerable Configurations

Part Description Count
Application
Oneclick_Cms
1
Application
Sisplet_Cms
1

Exploit-Db

descriptionSisplet CMS <= 05.10 (site_path) Remote File Inclusion Vulnerability. CVE-2007-2347. Webapps exploit for php platform
fileexploits/php/webapps/3667.txt
idEDB-ID:3667
last seen2016-01-31
modified2007-04-05
platformphp
port
published2007-04-05
reporterkezzap66345
sourcehttps://www.exploit-db.com/download/3667/
titleSisplet CMS <= 05.10 site_path Remote File Inclusion Vulnerability
typewebapps