Vulnerabilities > CVE-2007-2676 - Remote File Include vulnerability in Open Translation Engine Open Translation Engine 0.7.8

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
open-translation-engine
exploit available

Summary

PHP remote file inclusion vulnerability in skins/header.php in Open Translation Engine (OTE) 0.7.8 allows remote attackers to execute arbitrary PHP code via a URL in the ote_home parameter.

Vulnerable Configurations

Part Description Count
Application
Open_Translation_Engine
1

Exploit-Db

descriptionOpen Translation Engine (OTE) 0.7.8 (header.php ote_home) RFI Vuln. CVE-2007-2676. Webapps exploit for php platform
fileexploits/php/webapps/3838.txt
idEDB-ID:3838
last seen2016-01-31
modified2007-05-03
platformphp
port
published2007-05-03
reporterGoLd_M
sourcehttps://www.exploit-db.com/download/3838/
titleOpen Translation Engine OTE 0.7.8 header.php ote_home RFI Vuln
typewebapps