CVE-2007-6657: Code Injection
Published Jan 4, 2008
·Updated
PHP remote file inclusion vulnerability in source/includes/loadforum.php in Mihalism Multi Forum Host 3.0.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mfhrootpath parameter.
Affected Software
1 affected component
Mihalism Multi Host
Event History
Jan 4, 2008
CVE Published
11:46 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6657?
CVE-2007-6657 is considered a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2007-6657?
To fix CVE-2007-6657, upgrade to a later version of Mihalism Multi Forum Host that addresses this vulnerability.
3
Which versions are affected by CVE-2007-6657?
CVE-2007-6657 affects Mihalism Multi Forum Host 3.0.x and earlier versions.
4
What type of vulnerability is CVE-2007-6657?
CVE-2007-6657 is a remote file inclusion vulnerability allowing attackers to execute arbitrary PHP code.
5
What parameters are exploited in CVE-2007-6657?
The vulnerability is exploited through the mfh_root_path parameter in the source/includes/load_forum.php file.