CVE-2007-2254 Information

Description

PHP remote file inclusion vulnerability in admin/setup/level2.php in PHP Classifieds 6.04 and probably earlier versions allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter. NOTE: this product was referred to as \Allfaclassfieds\ in the original disclosure.

Reference

http://securityreason.com/securityalert/2618 http://www.attrition.org/pipermail/vim/2007-April/001543.html http://www.securityfocus.com/archive/1/466648/100/0/threaded https://exchange.xforce.ibmcloud.com/vulnerabilities/33798

Share on: