Vulnerabilities > CVE-2007-2596 - Remote File Include vulnerability in AForum Func.PHP

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
agner-fog
exploit available

Summary

PHP remote file inclusion vulnerability in common/func.php in aForum 1.32 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CommonAbsDir parameter.

Vulnerable Configurations

Part Description Count
Application
Agner_Fog
1

Exploit-Db

descriptionaForum <= 1.32 (CommonAbsDir) Remote File Inclusion Vulnerability. CVE-2007-2596,CVE-2007-2634. Webapps exploit for php platform
fileexploits/php/webapps/3884.txt
idEDB-ID:3884
last seen2016-01-31
modified2007-05-09
platformphp
port
published2007-05-09
reporterThE TiGeR
sourcehttps://www.exploit-db.com/download/3884/
titleaForum <= 1.32 CommonAbsDir Remote File Inclusion Vulnerability
typewebapps