{ "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2007-1458", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "Multiple PHP remote file inclusion vulnerabilities in CARE2X 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) inc_checkdate_lang.php, (2) inc_charset_fx.php, (3) inc_config_color.php, (4) inc_currency_set.php, (5) inc_db_makelink.php, (6) inc_diagnostics_report_fx.php, (7) inc_environment_global.php, (8) inc_front_chain_lang.php, (9) inc_init_crypt.php, (10) inc_load_copyrite.php, or (11) inc_news_save.php in include/; (12) diagnostics-report-index.php, (13) config_options_mascot.php, (14) barcode-labels.php, (15) chg-color.php, or (16) config_options_gui_template.php in main/; or unspecified other files." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "name": "24481", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/24481" }, { "name": "care2x-rootpath-file-include(32981)", "refsource": "XF", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/32981" }, { "name": "20070314 [ECHO_ADV_72$2007] CARE2X (root_path) Remote File Inclusion Vulnerability", "refsource": "BUGTRAQ", "url": "http://www.securityfocus.com/archive/1/462808/100/0/threaded" }, { "name": "34056", "refsource": "OSVDB", "url": "http://www.osvdb.org/34056" }, { "name": "34051", "refsource": "OSVDB", "url": "http://www.osvdb.org/34051" }, { "name": "34046", "refsource": "OSVDB", "url": "http://www.osvdb.org/34046" }, { "name": "34052", "refsource": "OSVDB", "url": "http://www.osvdb.org/34052" }, { "name": "34048", "refsource": "OSVDB", "url": "http://www.osvdb.org/34048" }, { "name": "34049", "refsource": "OSVDB", "url": "http://www.osvdb.org/34049" }, { "name": "34059", "refsource": "OSVDB", "url": "http://www.osvdb.org/34059" }, { "name": "34057", "refsource": "OSVDB", "url": "http://www.osvdb.org/34057" }, { "name": "34058", "refsource": "OSVDB", "url": "http://www.osvdb.org/34058" }, { "name": "34053", "refsource": "OSVDB", "url": "http://www.osvdb.org/34053" }, { "name": "http://advisories.echo.or.id/adv/adv72-theday-2007.txt", "refsource": "MISC", "url": "http://advisories.echo.or.id/adv/adv72-theday-2007.txt" }, { "name": "34060", "refsource": "OSVDB", "url": "http://www.osvdb.org/34060" }, { "name": "34050", "refsource": "OSVDB", "url": "http://www.osvdb.org/34050" }, { "name": "34045", "refsource": "OSVDB", "url": "http://www.osvdb.org/34045" }, { "name": "34055", "refsource": "OSVDB", "url": "http://www.osvdb.org/34055" }, { "name": "34047", "refsource": "OSVDB", "url": "http://www.osvdb.org/34047" }, { "name": "ADV-2007-0938", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2007/0938" }, { "name": "22951", "refsource": "BID", "url": "http://www.securityfocus.com/bid/22951" }, { "name": "34054", "refsource": "OSVDB", "url": "http://www.osvdb.org/34054" } ] } }