CVE-2007-0986

Properties

Published:
15.02.2007
Updated:
20.02.2007
Patch available:
Severity:
High
CVSS vector:
(AV:R/AC:H/Au:NR/C:C/I:C/A:C/B:N)
Product:
Jupiter CMS: Jupiter CMS

Vulnerability description

PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5, when PHP 5.0.0 or later is used, allows remote attackers to execute arbitrary PHP code via an ftp URL in the n parameter.

References:

BUGTRAQ: http://www.securityfocus.com/archive/1/archive/1/460076/100/0/threaded
BUGTRAQ: http://www.securityfocus.com/archive/1/archive/1/460100/100/0/threaded
http://mgsdl.free.fr/advisories/12070214.txt: http://mgsdl.free.fr/advisories/12070214.txt
http://www.acid-root.new.fr/advisories/12070214.txt: http://www.acid-root.new.fr/advisories/12070214.txt
Milw0rm: http://www.milw0rm.com/exploits/3309
BID: http://www.securityfocus.com/bid/22560