CVE-2007-0167
CVE-2007-0167
Multiple PHP file inclusion vulnerabilities in WGS-PPC (aka PPC Search Engine), as distributed with other aliases, allow remote attackers to execute arbitrary PHP code via a URL in the INC parameter in (1) config_admin.php, (2) config_main.php, (3) config_member.php, and (4) mysql_config.php in config/; (5) admin.php and (6) index.php in admini/; (7) paypalipn/ipnprocess.php; (8) index.php and (9) registration.php in members/; and (10) ppcbannerclick.php and (11) ppcclick.php in main/.
Affected products
n/a · n/apublic PoCs found — 1
cve_referencewww.exploit-db.com/exploits/3104unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://securityreason.com/securityalert/2134https://exchange.xforce.ibmcloud.com/vulnerabilities/31355https://www.exploit-db.com/exploits/3104http://www.attrition.org/pipermail/vim/2007-January/001221.htmlhttp://www.osvdb.org/33444http://www.osvdb.org/33445http://www.osvdb.org/33446http://www.osvdb.org/33447http://www.osvdb.org/33448http://www.osvdb.org/33449http://www.osvdb.org/33450http://www.osvdb.org/33451