CVE-2007-2311: High severity BloofoxCMS BloofoxCMS vulnerability
DISPUTED PHP remote file inclusion vulnerability in install/index.php in BlooFoxCMS 0.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the contentphp parameter. NOTE: this issue has been disputed by a reliable third party, stating that contentphp is initialized before use.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2311?
CVE-2007-2311 is a disputed remote file inclusion vulnerability that allows for the execution of arbitrary PHP code.
How do I fix CVE-2007-2311?
To fix CVE-2007-2311, ensure that user inputs are properly sanitized and avoid allowing untrusted URLs in the content_php parameter.
Which version of BlooFoxCMS is affected by CVE-2007-2311?
CVE-2007-2311 specifically affects BlooFoxCMS version 0.2.2.
What is the impact of exploiting CVE-2007-2311?
Exploiting CVE-2007-2311 can allow an attacker to execute arbitrary PHP code, potentially compromising the entire web server.
Is CVE-2007-2311 still a relevant threat today?
While CVE-2007-2311 is an older vulnerability, any software still in use without proper updates or mitigations remains at risk.