CVE-2007-2458
Multiple PHP remote file inclusion vulnerabilities in Pixaria Gallery before 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter to psg.smarty.lib.php and certain include and library scripts, a…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.1%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple PHP remote file inclusion vulnerabilities in Pixaria Gallery before 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter to psg.smarty.lib.php and certain include and library scripts, a different vector than CVE-2007-2457.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 10.13% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- pixaria/pixaria gallery
- Source
- cve@mitre.org
References
- http://pixaria.com/index.history.phpURL Repurposed
- http://secunia.com/advisories/24821Vendor Advisory
- http://www.pixaria.com/news/article/70/URL Repurposed
- http://www.pixaria.com/news/article/71/Patch, URL Repurposed
- http://www.vupen.com/english/advisories/2007/1390Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33662
- https://www.exploit-db.com/exploits/3733
- http://pixaria.com/index.history.phpURL Repurposed
- http://secunia.com/advisories/24821Vendor Advisory
- http://www.pixaria.com/news/article/70/URL Repurposed
- http://www.pixaria.com/news/article/71/Patch, URL Repurposed
- http://www.vupen.com/english/advisories/2007/1390Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33662
- https://www.exploit-db.com/exploits/3733
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.