First published: Wed Jan 31 2007(Updated: )
Multiple PHP remote file inclusion vulnerabilities in EncapsCMS 0.3.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) config[path] parameter to (a) common_foot.php or (b) blogs.php, or (2) the config[theme] parameter to (c) admin/gallery_head.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fipsasp Fipscms Light | =0.3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0635 is classified as a high severity vulnerability due to its capability to allow remote code execution.
To fix CVE-2007-0635, upgrade EncapsCMS to a version beyond 0.3.6 where the vulnerabilities have been patched.
CVE-2007-0635 affects common_foot.php, blogs.php, and admin/gallery_head.php within EncapsCMS 0.3.6.
Yes, CVE-2007-0635 can be exploited by unauthenticated attackers if they can send crafted URLs to the vulnerable components.
CVE-2007-0635 can result in remote file inclusion attacks, allowing attackers to execute arbitrary PHP code on the server.