Vulnerabilities > CVE-2007-2988 - Remote PHP Code Execution vulnerability in Inout Metasearch Engine Create_Engine.PHP

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
inout-scripts
exploit available

Summary

A certain admin script in Inout Meta Search Engine sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to inject arbitrary PHP code, as demonstrated by a request to admin/create_engine.php followed by a request to admin/generate_tabs.php.

Vulnerable Configurations

Part Description Count
Application
Inout_Scripts
1

Exploit-Db

descriptionInout Search Engine (all version) Remote Code Execution Exploit. CVE-2007-2988. Webapps exploit for php platform
fileexploits/php/webapps/4004.php
idEDB-ID:4004
last seen2016-01-31
modified2007-05-29
platformphp
port
published2007-05-29
reporterBlackHawk
sourcehttps://www.exploit-db.com/download/4004/
titleInout Search Engine - Remote Code Execution Exploit
typewebapps