CVE-2007-4009: Code Injection
Published Jul 26, 2007
·Updated
PHP remote file inclusion vulnerability in admin/businessinc/saveserver.php in SWSoft Confixx Pro 2.0.12 through 3.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the thisdir parameter.
Affected Software
2 affected components
Parallels Confixx=2.0.12
Parallels Confixx=3.3.1
Event History
Jul 26, 2007
CVE Published
12:30 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4009?
CVE-2007-4009 is classified as a critical vulnerability due to its potential for remote code execution.
2
How can I fix CVE-2007-4009?
To fix CVE-2007-4009, users should update their SWSoft Confixx Pro software to version 3.3.1 or later.
3
What are the affected software versions for CVE-2007-4009?
CVE-2007-4009 affects SWSoft Confixx Pro versions 2.0.12 through 3.3.1.
4
What type of attack does CVE-2007-4009 enable?
CVE-2007-4009 enables remote attackers to execute arbitrary PHP code on vulnerable systems.
5
What is the cause of the vulnerability in CVE-2007-4009?
The vulnerability in CVE-2007-4009 is caused by improper validation of user input in the thisdir parameter.