CVE-2007-1643 Information
Feb 14, 2021
cve
Description
Multiple PHP remote file inclusion vulnerabilities in LAN Management System (LMS) 1.8.9 Vala and earlier allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG[directories][userpanel_dir] parameter to userpanel.php or the (2) _LIB_DIR parameter to welcome.php.
Reference
http://secunia.com/advisories/24621 http://www.attrition.org/pipermail/vim/2007-April/001560.html http://www.securityfocus.com/bid/23099 http://www.securityfocus.com/bid/23100 http://www.vupen.com/english/advisories/2007/1086 https://exchange.xforce.ibmcloud.com/vulnerabilities/33158 https://www.exploit-db.com/exploits/3545
Share on: