Return to CVE list

CVE-2007-5054

7.5
Critical

CVE-2007-5054

cve@mitre.org
Modified

Description

Multiple PHP remote file inclusion vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the gsLanguage parameter to (1) search/search.php, (2) poll/inlinepoll.php, (3) poll/showpoll.php, (4) links/showlinks.php, or (5) links/submit_links.php in modules/.

Exploits

44412007-09-21webappsPHP

iziContents rc6 - Local/Remote File Inclusion

By irk4z