CVE-2007-1288 Information

Description

Multiple PHP remote file inclusion vulnerabilities in Webmobo WB News 1.4.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the config[installdir] parameter to (1) comment.php (2) themes.php (3) directory.php and (4) sendmsg.php in admin/.

Reference

http://osvdb.org/34951 http://osvdb.org/34952 http://osvdb.org/34953 http://osvdb.org/34954 http://securityreason.com/securityalert/2355 http://www.securityfocus.com/archive/1/461674/100/0/threaded https://exchange.xforce.ibmcloud.com/vulnerabilities/32774

Share on: