CVE-2007-4815 Information
Feb 14, 2021
cve
Description
Multiple PHP remote file inclusion vulnerabilities in WebED in Markus Iser ED Engine 0.8999 alpha allow remote attackers to execute arbitrary PHP code via a URL in the Codebase parameter to (1) channeledit.php (2) post.php (3) view.php or (4) viewitem.php in source/mod/rss/.
Reference
http://osvdb.org/38395 http://osvdb.org/38396 http://osvdb.org/38397 http://osvdb.org/38398 http://www.securityfocus.com/archive/1/480108/100/0/threaded http://www.securityfocus.com/bid/25608 http://www.vupen.com/english/advisories/2007/3171 https://exchange.xforce.ibmcloud.com/vulnerabilities/36532 https://www.exploit-db.com/exploits/4384
Share on: