Vulnerabilities > CVE-2007-3524 - Remote File Include and Information Disclosure vulnerability in Ripe Website Manager

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
ripe-website-manager
exploit available

Summary

Multiple PHP remote file inclusion vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the level parameter to (1) admin/includes/author_panel_header.php or (2) admin/includes/admin_header.php. Successful exploitation of this vulnerability requires that "register_globals" is enabled.

Vulnerable Configurations

Part Description Count
Application
Ripe_Website_Manager
1

Exploit-Db

descriptionRipe Website Manager (CMS) <= 0.8.9 Remote File Inclusion Vulns. CVE-2007-3524. Webapps exploit for php platform
fileexploits/php/webapps/4129.txt
idEDB-ID:4129
last seen2016-01-31
modified2007-06-30
platformphp
port
published2007-06-30
reporterBlackNDoor
sourcehttps://www.exploit-db.com/download/4129/
titleRipe Website Manager CMS <= 0.8.9 - Remote File Inclusion Vulns
typewebapps