CVE-2007-2298: High severity Gforge Garennes vulnerability
Published Apr 26, 2007
·Updated
Multiple PHP remote file inclusion vulnerabilities in Garennes 0.6.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the repertoireconfig parameter to index.php in (1) cpe/, (2) direction/, or (3) professeurs/.
Affected Software
1 affected component
Gforge Garennes<=0.6.1
Remediation
Patch Available
Event History
Apr 26, 2007
CVE Published
09:19 PM
Apr 27, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2298?
CVE-2007-2298 is classified as a critical severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2007-2298?
To mitigate CVE-2007-2298, upgrade Garennes to version 0.6.2 or later where this vulnerability is patched.
3
What types of attacks can CVE-2007-2298 enable?
CVE-2007-2298 can allow attackers to execute arbitrary PHP code on the affected systems.
4
Which versions of Garennes are affected by CVE-2007-2298?
CVE-2007-2298 affects Garennes versions 0.6.1 and earlier.
5
Where can CVE-2007-2298 be exploited?
CVE-2007-2298 can be exploited through the repertoire_config parameter in the index.php file within specific directories.