CVE-2007-4525: Code Injection
DISPUTED PHP remote file inclusion vulnerability in inc-calcul.php3 in SPIP 1.7.2 allows remote attackers to execute arbitrary PHP code via a URL in the squelettecache parameter, a different vector than CVE-2006-1702. NOTE: this issue has been disputed by third party researchers, stating that the squelettecache variable is initialized before use, and is only used within the scope of a function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4525?
The severity of CVE-2007-4525 is considered low due to the disputed nature of the vulnerability.
How do I fix CVE-2007-4525?
To fix CVE-2007-4525, users should upgrade to a patched version of SPIP beyond 1.7.2.
What type of vulnerability is CVE-2007-4525?
CVE-2007-4525 is classified as a remote file inclusion vulnerability.
Which versions of SPIP are affected by CVE-2007-4525?
CVE-2007-4525 affects SPIP version 1.7.2.
Can CVE-2007-4525 allow remote code execution?
Yes, CVE-2007-4525 may allow remote code execution if exploited.