Vulnerability Description
PHP remote file inclusion vulnerability in Trevorchan 0.7 and earlier allows remote attackers to execute arbitrary code via the tc_config[rootdir] parameter to (1) upgrade.php, (2) paint_save.php, (3) menu.php, (4) manage.php, and (5) banned.php. NOTE: his issue has been disputed by reliable third parties, who state that the variable is set before use in config.php
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trevorchan | Trevorchan | <= 0.7 |
References
- http://osvdb.org/33475
- http://securitytracker.com/id?1017512
- http://www.attrition.org/pipermail/vim/2007-January/001241.html
- http://osvdb.org/33475
- http://securitytracker.com/id?1017512
- http://www.attrition.org/pipermail/vim/2007-January/001241.html
FAQ
What is CVE-2007-0863?
CVE-2007-0863 is a vulnerability with a CVSS score of 10.0 (HIGH). PHP remote file inclusion vulnerability in Trevorchan 0.7 and earlier allows remote attackers to execute arbitrary code via the tc_config[rootdir] parameter to (1) upgrade.php, (2) paint_save.php, (3)...
How severe is CVE-2007-0863?
CVE-2007-0863 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-0863?
Check the references section above for vendor advisories and patch information. Affected products include: Trevorchan Trevorchan.