CVE-2007-1643
Multiple PHP remote file inclusion vulnerabilities in LAN Management System (LMS) 1.8.9 Vala and earlier allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG[directories][userpanel_dir] parameter to userpanel.php or the (2)…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.7%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple PHP remote file inclusion vulnerabilities in LAN Management System (LMS) 1.8.9 Vala and earlier allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG[directories][userpanel_dir] parameter to userpanel.php or the (2) _LIB_DIR parameter to welcome.php.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 10.68% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- lan management system/lan management system
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/24621Vendor Advisory
- http://www.attrition.org/pipermail/vim/2007-April/001560.html
- http://www.securityfocus.com/bid/23099Exploit
- http://www.securityfocus.com/bid/23100Exploit
- http://www.vupen.com/english/advisories/2007/1086Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33158
- https://www.exploit-db.com/exploits/3545
- http://secunia.com/advisories/24621Vendor Advisory
- http://www.attrition.org/pipermail/vim/2007-April/001560.html
- http://www.securityfocus.com/bid/23099Exploit
- http://www.securityfocus.com/bid/23100Exploit
- http://www.vupen.com/english/advisories/2007/1086Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33158
- https://www.exploit-db.com/exploits/3545
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.