CVE-2007-2199
PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vincent Blavet PhpConcept Library, as used in multiple products including (1) Joomla!
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 46.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vincent Blavet PhpConcept Library, as used in multiple products including (1) Joomla! 1.5.0 Beta, (2) N/X Web Content Management System (WCMS) 4.5, (3) CJG EXPLORER PRO 3.3, and (4) phpSiteBackup 0.1, allows remote attackers to execute arbitrary PHP code via a URL in the g_pcltar_lib_dir parameter.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 46.76% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- cjg explorer pro/cjg explorer pro · joomla/joomla · nx/n x wcms · phpsitebackup/phpsitebackup
- Source
- cve@mitre.org
References
- http://osvdb.org/34803
- http://osvdb.org/36009
- http://secunia.com/advisories/25230Vendor Advisory
- http://www.attrition.org/pipermail/vim/2007-May/001618.html
- http://www.hackers.ir/advisories/joomla.htmlExploit, Vendor Advisory
- http://www.securityfocus.com/archive/1/466687/100/0/threaded
- http://www.securityfocus.com/archive/1/478503/100/0/threaded
- http://www.securityfocus.com/bid/23613
- http://www.securityfocus.com/bid/23708
- http://www.securityfocus.com/bid/24660
- http://www.securityfocus.com/bid/25528
- http://www.vupen.com/english/advisories/2007/1511Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33837
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34273
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35092
- https://www.exploit-db.com/exploits/3781
- https://www.exploit-db.com/exploits/3915
- https://www.exploit-db.com/exploits/4111
- http://osvdb.org/34803
- http://osvdb.org/36009
- http://secunia.com/advisories/25230Vendor Advisory
- http://www.attrition.org/pipermail/vim/2007-May/001618.html
- http://www.hackers.ir/advisories/joomla.htmlExploit, Vendor Advisory
- http://www.securityfocus.com/archive/1/466687/100/0/threaded
- http://www.securityfocus.com/archive/1/478503/100/0/threaded
- http://www.securityfocus.com/bid/23613
- http://www.securityfocus.com/bid/23708
- http://www.securityfocus.com/bid/24660
- http://www.securityfocus.com/bid/25528
- http://www.vupen.com/english/advisories/2007/1511Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.