Vulnerabilities > CVE-2007-3524 - Remote File Include and Information Disclosure vulnerability in Ripe Website Manager
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Multiple PHP remote file inclusion vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the level parameter to (1) admin/includes/author_panel_header.php or (2) admin/includes/admin_header.php. Successful exploitation of this vulnerability requires that "register_globals" is enabled.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Ripe Website Manager (CMS) <= 0.8.9 Remote File Inclusion Vulns. CVE-2007-3524. Webapps exploit for php platform |
file | exploits/php/webapps/4129.txt |
id | EDB-ID:4129 |
last seen | 2016-01-31 |
modified | 2007-06-30 |
platform | php |
port | |
published | 2007-06-30 |
reporter | BlackNDoor |
source | https://www.exploit-db.com/download/4129/ |
title | Ripe Website Manager CMS <= 0.8.9 - Remote File Inclusion Vulns |
type | webapps |