CVE-2007-5160: Code Injection
Multiple PHP remote file inclusion vulnerabilities in Thierry Leriche Restaurant Management System (ReMaSys) 0.5 allow remote attackers to execute arbitrary PHP code via a URL in (1) the DIRROOT parameter to (a) global.php, or the (2) DIRPAGE parameter to (b) template/fr/page.php or (c) page/fr/boxConnection.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5160?
CVE-2007-5160 is rated as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2007-5160?
To fix CVE-2007-5160, update to a version of Restaurant Management System later than 0.5 that addresses these vulnerabilities.
What types of attacks can be executed via CVE-2007-5160?
CVE-2007-5160 allows remote attackers to execute arbitrary PHP code on the vulnerable system.
Which parameters are exploited in CVE-2007-5160?
CVE-2007-5160 exploits the DIR_ROOT parameter in global.php and the DIR_PAGE parameter in specific template and page files.
What versions of Restaurant Management System are affected by CVE-2007-5160?
CVE-2007-5160 affects version 0.5 of the Restaurant Management System.