Vulnerabilities > CVE-2007-2762 - Remote File Include vulnerability in Build IT Fast Build IT Fast 0.4.1

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
build-it-fast
exploit available

Summary

Multiple PHP remote file inclusion vulnerabilities in Build it Fast (bif3) 0.4.1 allow remote attackers to execute arbitrary PHP code via a URL in (1) the pear_dir parameter to Base/Application.php, or the (2) sys_dir parameter to (a) Footer.php, (b) widget.BifContainer.php, (c) widget.BifRoot.php, (d) widget.BifRoot2.php, (e) widget.BifRoot3.php, or (f) widget.BifWarning.php in Widgets/Base/.

Vulnerable Configurations

Part Description Count
Application
Build_It_Fast
1

Exploit-Db

descriptionBuild it Fast (bif3) 0.4.1 Multiple Remote File Inclusion Vulnerabilities. CVE-2007-2762. Webapps exploit for php platform
fileexploits/php/webapps/3947.txt
idEDB-ID:3947
last seen2016-01-31
modified2007-05-17
platformphp
port
published2007-05-17
reporterAlkomandoz Hacker
sourcehttps://www.exploit-db.com/download/3947/
titleBuild it Fast bif3 0.4.1 - Multiple Remote File Inclusion Vulnerabilities
typewebapps