Vulnerabilities > CVE-2007-3141 - Remote Security vulnerability in PHPwebthings 1.5.2

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
phpwebthings
exploit available

Summary

PHP remote file inclusion vulnerability in core/editor.php in phpWebThings 1.5.2 allows remote attackers to execute arbitrary PHP code via a URL in the editor_insert_top parameter. NOTE: the editor_insert_bottom vector is already covered by CVE-2006-6042.

Vulnerable Configurations

Part Description Count
Application
Phpwebthings
1

Exploit-Db

descriptionphpWebThings <= 1.5.2 (editor.php) Remote File Include Vulnerability. CVE-2006-6042,CVE-2007-3141. Webapps exploit for php platform
fileexploits/php/webapps/2811.txt
idEDB-ID:2811
last seen2016-01-31
modified2006-11-18
platformphp
port
published2006-11-18
reporternuffsaid
sourcehttps://www.exploit-db.com/download/2811/
titlephpWebThings <= 1.5.2 editor.php Remote File Include Vulnerability
typewebapps