"value":"Multiple PHP remote file inclusion vulnerabilities in ELSEIF CMS Beta 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) contenus parameter to (a) contenus.php; the (2) tpelseifportalrepertoire parameter to (b) votes.php, (c) espaceperso.php, (d) enregistrement.php, (e) commentaire.php, and (f) coeurusr.php in utilisateurs/, and (g) articles/fonctions.php and (h) depot/fonctions.php in moduleajouter/; the (3) corpsdesign parameter to (i) articles/usrarticles.php and (j) depot/usrdepot.php in moduleajouter/; and possibly other files."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"n/a"
}
]
}
]
},
"references":{
"reference_data":[
{
"name":"38656",
"refsource":"OSVDB",
"url":"http://osvdb.org/38656"
},
{
"name":"38649",
"refsource":"OSVDB",
"url":"http://osvdb.org/38649"
},
{
"name":"38651",
"refsource":"OSVDB",
"url":"http://osvdb.org/38651"
},
{
"name":"38653",
"refsource":"OSVDB",
"url":"http://osvdb.org/38653"
},
{
"name":"25951",
"refsource":"BID",
"url":"http://www.securityfocus.com/bid/25951"
},
{
"name":"38652",
"refsource":"OSVDB",
"url":"http://osvdb.org/38652"
},
{
"name":"38658",
"refsource":"OSVDB",
"url":"http://osvdb.org/38658"
},
{
"name":"38654",
"refsource":"OSVDB",
"url":"http://osvdb.org/38654"
},
{
"name":"38650",
"refsource":"OSVDB",
"url":"http://osvdb.org/38650"
},
{
"name":"38655",
"refsource":"OSVDB",
"url":"http://osvdb.org/38655"
},
{
"name":"20071006 Else If cms Multiple Remote vulnerabilities",