Vulnerabilities > CVE-2007-3370 - Remote File Include vulnerability in KIM Kyoung MIN SUN Board 1.00.00Alpha

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
kim-kyoung-min
exploit available

Summary

Multiple PHP remote file inclusion vulnerabilities in Sun Board 1.00.00 Alpha allow remote attackers to execute arbitrary PHP code via a URL in (1) the sunPath parameter to include.php or (2) the dir parameter to skin/board/default/doctype.php.

Vulnerable Configurations

Part Description Count
Application
Kim_Kyoung_Min
1

Exploit-Db

descriptionSun Board 1.00.00 alpha Remote File Inclusion Vulnerabilities. CVE-2007-3370. Webapps exploit for php platform
fileexploits/php/webapps/4091.txt
idEDB-ID:4091
last seen2016-01-31
modified2007-06-22
platformphp
port
published2007-06-22
reporterGoLd_M
sourcehttps://www.exploit-db.com/download/4091/
titleSun Board 1.00.00 alpha Remote File Inclusion Vulnerabilities
typewebapps