CVE-2007-5599 Information

Description

Multiple PHP remote file inclusion vulnerabilities in awrate 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the toroot parameter to (1) 404.php or (2) topbar.php different vectors than CVE-2006-6368.

Reference

http://arfis.wordpress.com/2007/09/13/rfi-02-awratecom-message-board/ http://osvdb.org/45528 http://osvdb.org/45529 http://www.securityfocus.com/bid/26336

Share on: