PT-2007-2532 · Php · Php-Mip

Gold_M

·

Published

2007-02-26

·

Updated

2017-10-11

·

CVE-2007-1104

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions PHP Module Implementation (PHP-MIP) version 0.1
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the laypath parameter. This is a result of a remote file inclusion vulnerability in the top.php file.
Recommendations For PHP Module Implementation (PHP-MIP) version 0.1, avoid using the laypath parameter in the affected API endpoint until the issue is resolved. As a temporary workaround, consider restricting access to the top.php file to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1104

Affected Products

Php-Mip