CVE-2007-6488: Input Validation
Published Dec 20, 2007
·Updated
Multiple PHP remote file inclusion vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in (1) the dir[classes] parameter to sitemap.xml.php or (2) the error parameter to errors.php.
Affected Software
1 affected component
Falcon Series One CMS=1.4.3
Event History
Dec 20, 2007
CVE Published
08:46 PM
Dec 21, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6488?
CVE-2007-6488 is considered a critical vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2007-6488?
To mitigate CVE-2007-6488, upgrade Falcon Series One CMS to the latest version that addresses these vulnerabilities.
3
What are the affected versions for CVE-2007-6488?
CVE-2007-6488 affects Falcon Series One CMS version 1.4.3.
4
What types of attacks can exploit CVE-2007-6488?
CVE-2007-6488 can be exploited by attackers to execute arbitrary PHP code on the server.
5
Can CVE-2007-6488 impact data integrity?
Yes, exploiting CVE-2007-6488 can lead to unauthorized access and potential compromise of data integrity.