CVE-2007-4886: Code Injection
Published Sep 14, 2007
·Updated
Incomplete blacklist vulnerability in index.php in AuraCMS 1.x and probably 2.x allows remote attackers to execute arbitrary PHP code via a (1) UNC share pathname, or a (2) ftp, (3) ftps, or (4) ssh2.sftp URL, in the pilih parameter, for which PHP remote file inclusion is blocked only for http URLs.
Affected Software
10 affected components
AuraCMS AuraCMS=1.0
AuraCMS AuraCMS=1.1
AuraCMS AuraCMS=1.2
AuraCMS AuraCMS=1.3
AuraCMS AuraCMS=1.5
AuraCMS AuraCMS=1.6_beta
AuraCMS AuraCMS=1.61
AuraCMS AuraCMS=1.62
AuraCMS AuraCMS=2.0
AuraCMS AuraCMS=2.1
Event History
Sep 14, 2007
CVE Published
12:17 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4886?
CVE-2007-4886 is considered a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2007-4886?
To fix CVE-2007-4886, update AuraCMS to the latest version where the vulnerability has been patched.
3
What versions of AuraCMS are affected by CVE-2007-4886?
CVE-2007-4886 affects AuraCMS versions 1.0 to 2.1.
4
What type of attack does CVE-2007-4886 enable?
CVE-2007-4886 enables remote attackers to execute arbitrary PHP code through certain URL parameters.
5
Is this vulnerability specific to any URL protocols in CVE-2007-4886?
Yes, CVE-2007-4886 allows exploitation via UNC, ftp, ftps, and ssh2.sftp URL protocols.