CVE-2007-4737: Code Injection
Published Sep 6, 2007
·Updated
Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the STPHPLIBDIR parameter to (1) stphpapplication.php, (2) stphpbtnimage.php, or (3) stphpform.php.
Affected Software
1 affected component
SpeedTech STPHPLibrary=0.8.0
Event History
Sep 6, 2007
CVE Published
07:17 PM
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4737?
CVE-2007-4737 is considered to have a high severity due to its potential to allow arbitrary PHP code execution.
2
How do I fix CVE-2007-4737?
To fix CVE-2007-4737, ensure that the STPHPLIB_DIR parameter is properly sanitized and validate input to prevent remote file inclusion.
3
Which versions of the SpeedTech PHP Library are affected by CVE-2007-4737?
CVE-2007-4737 affects SpeedTech PHP Library version 0.8.0.
4
What types of systems are impacted by CVE-2007-4737?
CVE-2007-4737 impacts systems using the SpeedTech PHP Library specifically version 0.8.0.
5
Can CVE-2007-4737 be exploited remotely?
Yes, CVE-2007-4737 can be exploited remotely by attackers to execute arbitrary PHP code.