Vulnerabilities > Canebluem > Mospray > 1.8.rc1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2006-07-25 | CVE-2006-3847 | Code Injection vulnerability in Canebluem Mospray 1.8Rc1 PHP remote file inclusion vulnerability in (1) admin.php, and possibly (2) details.php, (3) modify.php, (4) newgroup.php, (5) newtask.php, and (6) rss.php, in MoSpray (aka com_mospray) 1.8 RC1 allows remote attackers to execute arbitrary PHP code via a URL in the basedir parameter. | 5.1 |