[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2007-1790Date: (C)2007-03-31   (M)2023-12-22


Multiple PHP remote file inclusion vulnerabilities in Kaqoo Auction Software Free Edition allow remote attackers to execute arbitrary PHP code via a URL in the install_root parameter to (1) support.inc.php, (2) function.inc.php, (3) rdal_object.inc.php, (4) rdal_editor.inc.php. (5) login.inc.php, (6) request.inc.php, and (7) categories.inc.php in include/core/; (8) save.inc.php, (9) preview.inc.php, (10) edit_item.inc.php, (11) new_item.inc.php, and (12) item_info.inc.php in include/display/item/; (13) search.inc.php, (14) item_edit.inc.php, (15) register_succsess.inc.php, (16) context_menu.inc.php, (17) item_repost.inc.php, (18) balance.inc.php, (19) featured.inc.php, (20) user.inc.php, (21) buynow.inc.php, (22) install_complete.inc.php, (23) fees_info.inc.php, (24) user_feedback.inc.php, (25) admin_balance.inc.php, (26) activate.inc.php, (27) user_info.inc.php, (28) member.inc.php, (29) add_bid.inc.php, (30) items_filter.inc.php, (31) my_info.inc.php, (32) register.inc.php, (33) leave_feedback.inc.php, and (34) user_auctions.inc.php in include/display/; and (35) design/form.inc.php, (36) processor.inc.php, (37) interfaces.inc.php (38) left_menu.inc.php, (39) login.inc.php, and (40) categories.inc.php in include/.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.8
Exploit Score: 8.6
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
BID-23211
SECUNIA-24696
OSVDB-34545
OSVDB-34546
OSVDB-34547
OSVDB-34548
OSVDB-34549
OSVDB-34550
OSVDB-34551
OSVDB-34552
OSVDB-34553
OSVDB-34554
OSVDB-34555
OSVDB-34556
OSVDB-34557
OSVDB-34558
OSVDB-34559
OSVDB-34560
OSVDB-34561
OSVDB-34562
OSVDB-34563
OSVDB-34564
OSVDB-34565
OSVDB-34566
OSVDB-34567
OSVDB-34568
OSVDB-34569
OSVDB-34570
OSVDB-34571
OSVDB-34572
OSVDB-34573
OSVDB-34574
OSVDB-34575
OSVDB-34576
OSVDB-34577
OSVDB-34578
OSVDB-34579
OSVDB-34580
OSVDB-34581
OSVDB-34582
OSVDB-34583
OSVDB-34584
EXPLOIT-DB-3607
ADV-2007-1180
kaqoo-installroot-file-include(33335)

CWE    1
CWE-94

© SecPod Technologies