VulnerabilityModified
CVE-2007-0986
PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5, when PHP 5.0.0 or later is used, allows remote attackers to execute arbitrary PHP code via an ftp URL in the n parameter.
MEDIUM 5.1EPSS 3.29%
Does this matter?
Lower severity and a low EPSS score (3.29%). Track it; it rarely justifies an emergency change on its own.
Description
PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5, when PHP 5.0.0 or later is used, allows remote attackers to execute arbitrary PHP code via an ftp URL in the n parameter.
- CVSS 2.0
- 5.1 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
- EPSS
- 3.29% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- jupiter cms/jupiter cms
- Source
- cve@mitre.org
References
- http://mgsdl.free.fr/advisories/12070214.txtExploit, Vendor Advisory
- http://osvdb.org/33730
- http://www.acid-root.new.fr/advisories/12070214.txtExploit, Vendor Advisory
- http://www.securityfocus.com/archive/1/460076/100/0/threaded
- http://www.securityfocus.com/archive/1/460100/100/0/threaded
- http://www.securityfocus.com/bid/22560Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32519
- https://www.exploit-db.com/exploits/3309
- http://mgsdl.free.fr/advisories/12070214.txtExploit, Vendor Advisory
- http://osvdb.org/33730
- http://www.acid-root.new.fr/advisories/12070214.txtExploit, Vendor Advisory
- http://www.securityfocus.com/archive/1/460076/100/0/threaded
- http://www.securityfocus.com/archive/1/460100/100/0/threaded
- http://www.securityfocus.com/bid/22560Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32519
- https://www.exploit-db.com/exploits/3309
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.