CVE-2007-4949 Information
Description
LICENSE README.md cvefilelist cvelist nvdcve nvdpages.sh scripts test-CVE-2017-1882.markdown test-CVE-2017-18822.markdown tmpvendorlinks DISPUTED LICENSE README.md cvefilelist cvelist nvdcve nvdpages.sh scripts test-CVE-2017-1882.markdown test-CVE-2017-18822.markdown tmpvendorlinks Multiple PHP remote file inclusion vulnerabilities in php(Reactor) 1.2.7pl1 allow remote attackers to execute arbitrary PHP code via a URL in the pathtohomedir parameter to (1) ekilat.com-int.tpl.php (2) phpreactor.org-top.tpl.php or (3) ekilat.com-top.tpl.php in examples/. NOTE: this issue has been disputed by CVE since the vulnerability is present only when the product is incorrectly installed by placing examples/ under the web root.
Reference
http://arfis.wordpress.com/2007/09/14/rfi-03-phpreactor/ http://osvdb.org/43139
Share on: