CVE-2007-1626: Critical severity PHP-Nuke iFrame Module vulnerability
Published Mar 23, 2007
·Updated
PHP remote file inclusion vulnerability in iframe.php in the iFrame Module for PHP-NUKE allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.
Affected Software
1 affected component
PHP-Nuke iFrame Module
Event History
Mar 23, 2007
CVE Published
09:19 PM
Mar 24, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1626?
CVE-2007-1626 is considered a critical security vulnerability that allows remote attackers to execute arbitrary PHP code.
2
How do I fix CVE-2007-1626?
To fix CVE-2007-1626, update the iFrame Module for PHP-NUKE to a version that addresses the remote file inclusion issue.
3
What software is affected by CVE-2007-1626?
CVE-2007-1626 affects the iFrame Module for PHP-NUKE.
4
What kind of attacks are possible with CVE-2007-1626?
Exploiting CVE-2007-1626 can allow attackers to execute arbitrary PHP code, leading to full system compromise.
5
Is there a workaround for CVE-2007-1626?
A temporary workaround for CVE-2007-1626 is to disable the iFrame Module until a patch is applied.