CVE-2007-4834 Information

Description

Multiple PHP remote file inclusion vulnerabilities in phpRealty 0.02 allow remote attackers to execute arbitrary PHP code via a URL in the MGR parameter to (1) index.php (2) p_ins.php and (3) u_ins.php in manager/admin/.

Reference

http://osvdb.org/37074 http://osvdb.org/37075 http://osvdb.org/37076 http://www.securityfocus.com/bid/25610 https://exchange.xforce.ibmcloud.com/vulnerabilities/36518 https://www.exploit-db.com/exploits/4387

Share on: