First published: Mon Jan 29 2007(Updated: )
Multiple PHP remote file inclusion vulnerabilities in cmsimple/cms.php in CMSimple 2.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) pth[file][config] and (2) pth[file][image] parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CMS Made Simple | =2.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0551 is categorized with a high severity level due to the potential for remote code execution.
To fix CVE-2007-0551, it is recommended to upgrade to the latest version of CMSimple to eliminate the remote file inclusion vulnerabilities.
CVE-2007-0551 allows attackers to execute arbitrary PHP code, which can lead to complete system compromise.
CVE-2007-0551 specifically affects CMSimple version 2.7.
Yes, there are known exploits that target the vulnerabilities in CVE-2007-0551 for remote code execution.