CVE-2007-1967
PHP remote file inclusion vulnerability in index.php in stat12 allows remote attackers to execute arbitrary PHP code via a URL in the langpath parameter.
Does this matter?
Lower severity and a low EPSS score (1.34%). Track it; it rarely justifies an emergency change on its own.
Description
PHP remote file inclusion vulnerability in index.php in stat12 allows remote attackers to execute arbitrary PHP code via a URL in the langpath parameter. NOTE: this issue was published by an unreliable researcher, and there is little information to determine which product is actually affected. This is probably an invalid report based on analysis by CVE and a third party
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.34% probability · 70th percentile
- CISA KEV
- Not listed
- Affected
- stat12/stat12
- Source
- cve@mitre.org
References
- http://securityreason.com/securityalert/2555
- http://www.attrition.org/pipermail/vim/2007-April/001488.html
- http://www.attrition.org/pipermail/vim/2007-April/001508.html
- http://www.securityfocus.com/archive/1/464582/100/0/threaded
- http://securityreason.com/securityalert/2555
- http://www.attrition.org/pipermail/vim/2007-April/001488.html
- http://www.attrition.org/pipermail/vim/2007-April/001508.html
- http://www.securityfocus.com/archive/1/464582/100/0/threaded
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.