Vulnerabilities > CVE-2007-3451 - Remote File Include vulnerability in 6ALBlog

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
gorani-network
exploit available

Summary

PHP remote file inclusion vulnerability in admin/index.php in 6ALBlog allows remote authenticated administrators to execute arbitrary PHP code via a URL in the pg parameter.

Vulnerable Configurations

Part Description Count
Application
Gorani_Network
1

Exploit-Db

description6ALBlog (newsid) Remote SQL Injection Vulnerability. CVE-2007-3449,CVE-2007-3450,CVE-2007-3451. Webapps exploit for php platform
fileexploits/php/webapps/4104.txt
idEDB-ID:4104
last seen2016-01-31
modified2007-06-25
platformphp
port
published2007-06-25
reporterCrackers_Child
sourcehttps://www.exploit-db.com/download/4104/
title6ALBlog newsid Remote SQL Injection Vulnerability
typewebapps