PT-2007-3438 · Hinton Design · Phphd Download System

Published

2007-04-18

·

Updated

2018-10-16

·

CVE-2007-2096

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Hinton Design PHPHD Download System (phphd downloads) versions from 2006
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the phphd real path parameter. This is a PHP remote file inclusion vulnerability in the common.php file.
Recommendations For versions from 2006, consider restricting access to the phphd real path parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2096

Affected Products

Phphd Download System