CVE-2007-5573: Code Injection
Published Oct 18, 2007
·Updated
PHP remote file inclusion vulnerability in classes/core/language.php in LimeSurvey 1.5.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter.
Affected Software
1 affected component
Limesurvey LimeSurvey<=1.5.2
Event History
Oct 18, 2007
CVE Published
09:17 PM
Oct 19, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5573?
CVE-2007-5573 is considered critical due to its potential for remote code execution.
2
How do I fix CVE-2007-5573?
To fix CVE-2007-5573, upgrade LimeSurvey to a version later than 1.5.2.
3
What versions of LimeSurvey are affected by CVE-2007-5573?
CVE-2007-5573 affects LimeSurvey version 1.5.2 and earlier.
4
Can CVE-2007-5573 be exploited remotely?
Yes, CVE-2007-5573 can be exploited remotely by attackers.
5
What type of vulnerability is CVE-2007-5573?
CVE-2007-5573 is classified as a remote file inclusion vulnerability.