Vulnerability Description
PHP remote file inclusion vulnerability in tracking.php in Trackeur 1 allows remote attackers to execute arbitrary PHP code via a URL in the header parameter. NOTE: CVE and a third party dispute this vulnerability because header is defined before use. The researcher is known to be unreliable
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trackeur | Trackeur | 1 |
References
- http://www.securityfocus.com/archive/1/476671/100/0/threaded
- http://www.securityfocus.com/archive/1/476757/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36046
- http://www.securityfocus.com/archive/1/476671/100/0/threaded
- http://www.securityfocus.com/archive/1/476757/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36046
FAQ
What is CVE-2007-4383?
CVE-2007-4383 is a vulnerability with a CVSS score of 6.8 (MEDIUM). PHP remote file inclusion vulnerability in tracking.php in Trackeur 1 allows remote attackers to execute arbitrary PHP code via a URL in the header parameter. NOTE: CVE and a third party dispute this...
How severe is CVE-2007-4383?
CVE-2007-4383 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-4383?
Check the references section above for vendor advisories and patch information. Affected products include: Trackeur Trackeur.