First published: Thu Dec 20 2007(Updated: )
Multiple PHP remote file inclusion vulnerabilities in Form tools 1.5.0b allow remote attackers to execute arbitrary PHP code via a URL in the g_root_dir parameter to (1) admin_page_open.php and (2) client_page_open.php in global/templates/.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Usualtool CMS | =1.5.0b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6464 is considered a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2007-6464, upgrade to a later version of Form Tools that has addressed this remote file inclusion vulnerability.
Exploiting CVE-2007-6464 can lead to unauthorized execution of arbitrary PHP code on the affected server.
CVE-2007-6464 affects Form Tools version 1.5.0b specifically.
CVE-2007-6464 involves the 'g_root_dir' parameter in the files admin_page_open.php and client_page_open.php.