PT-2007-3330 · Php · Phpexplorator

Published

2007-04-12

·

Updated

2018-10-16

·

CVE-2007-1985

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions phpexplorator version 2.0
Description The issue allows remote attackers to execute arbitrary PHP code. This is achieved by providing a URL in the cmd or lang path parameter.
Recommendations For phpexplorator version 2.0, consider restricting access to the cmd and lang path parameters to prevent remote file inclusion attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1985

Affected Products

Phpexplorator