Multiple PHP remote file inclusion... CVE-2007-4738 CNNVD-200709-051

7.5 AV AC AU C I A
发布: 2007-09-06
修订: 2017-07-29

SpeedTech PHP Library (STPHPLibrary) 0.8.0版本中存在多个PHP远程文件包含漏洞。远程攻击者可以借助(1) db_conf 或 (2) 对utils/stphpimage_show.php的ADODB_DIR参数中的一个URL; 或对(3) stphpbutton.php, (4) stphpcheckbox.php, (5) stphpcheckboxwithcaption.php, (6) stphpcheckgroup.php, (7) stphpcomponent.php, (8) stphpcontrolwithcaption.php, (9) stphpedit.php, (10) stphpeditwithcaption.php, (11) stphphr.php, (12) stphpimage.php, (13) stphpimagewithcaption.php, (14) stphplabel.php, (15) stphplistbox.php, (16) stphplistboxwithcaption.php, (17) stphplocale.php, (18) stphppanel.php, (19) stphpradiobutton.php, (20) stphpradiobuttonwithcaption.php, (21) stphpradiogroup.php, (22) stphprichbutton.php, (23) stphpspacer.php, (24) stphptable.php, (25) stphptablecell.php, (26) stphptablerow.php, (27) stphptabpanel.php, (28) stphptabtitle.php, (29) stphptextarea.php, (30) stphptextareawithcaption.php, (31) stphptoolbar.php, (32) stphpwindow.php, (33) stphpxmldoc.php, or (34) stphpxmlelement.php的STPHPLIB_DIR参数中的URL, 执行任意PHP代码。

0%
当前有1条漏洞利用/PoC
当前有1条受影响产品信息