Multiple PHP remote file inclusion vulnerabilities in SimpGB 1.46.0 allow remote attackers to execute arbitrary PHP code via a URL in the path_simpgb parameter to (1) guestbook.php, (2) search.php, (3) mailer.php, (4) avatars.php, (5) ccode.php, (6) comments.php, (7) emoticons.php, (8) gbdownload.php, and possibly other PHP scripts.
References
Configurations
History
14 Feb 2024, 01:17
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.xmors-seurity.com/advisory/SimpGB%28rfi%29.txt - URL Repurposed |
07 Nov 2023, 02:00
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2007-05-24 19:30
Updated : 2024-02-28 11:01
NVD link : CVE-2007-2859
Mitre link : CVE-2007-2859
CVE.ORG link : CVE-2007-2859
JSON object : View
Products Affected
simpgb
- simpgb
CWE