CVE-2007-1986: High severity barnraiser AROUNDMe vulnerability
Multiple PHP remote file inclusion vulnerabilities in barnraiser AROUNDMe 0.7.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) languagepathcore parameter to inc/coreprofile.header.php, the (2) templatepathcore parameter to template/barnraiser01/maintcontactview.tpl.php, and the (3) templatepath parameter to template/barnraiser01/default.tpl.php. NOTE: this issue might overlap CVE-2006-5533.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1986?
CVE-2007-1986 has a severity rating that indicates a high risk due to the potential for arbitrary PHP code execution.
How do I fix CVE-2007-1986?
To fix CVE-2007-1986, update barnraiser AROUNDMe to a version that addresses these remote file inclusion vulnerabilities.
What software is affected by CVE-2007-1986?
CVE-2007-1986 affects barnraiser AROUNDMe version 0.7.7.
What type of vulnerability is CVE-2007-1986?
CVE-2007-1986 is classified as a remote file inclusion vulnerability.
Can CVE-2007-1986 be exploited remotely?
Yes, CVE-2007-1986 can be exploited remotely, allowing attackers to execute arbitrary PHP code.