{ "id": "CVE-2007-4738", "sourceIdentifier": "cve@mitre.org", "published": "2007-09-06T19:17:00.000", "lastModified": "2024-11-21T00:36:20.027", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) db_conf or (2) ADODB_DIR parameter to utils/stphpimage_show.php; or a URL in the STPHPLIB_DIR parameter to (3) stphpbutton.php, (4) stphpcheckbox.php, (5) stphpcheckboxwithcaption.php, (6) stphpcheckgroup.php, (7) stphpcomponent.php, (8) stphpcontrolwithcaption.php, (9) stphpedit.php, (10) stphpeditwithcaption.php, (11) stphphr.php, (12) stphpimage.php, (13) stphpimagewithcaption.php, (14) stphplabel.php, (15) stphplistbox.php, (16) stphplistboxwithcaption.php, (17) stphplocale.php, (18) stphppanel.php, (19) stphpradiobutton.php, (20) stphpradiobuttonwithcaption.php, (21) stphpradiogroup.php, (22) stphprichbutton.php, (23) stphpspacer.php, (24) stphptable.php, (25) stphptablecell.php, (26) stphptablerow.php, (27) stphptabpanel.php, (28) stphptabtitle.php, (29) stphptextarea.php, (30) stphptextareawithcaption.php, (31) stphptoolbar.php, (32) stphpwindow.php, (33) stphpxmldoc.php, or (34) stphpxmlelement.php, a different set of vectors than CVE-2007-4737. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information." }, { "lang": "es", "value": "M\u00faltiples vulnerabilidades de inclusi\u00f3n remota de archivos PHP en SpeedTech PHP Library (STPHPLibrary) versi\u00f3n 0.8.0, permiten a atacantes remotos ejecutar c\u00f3digo PHP arbitrario por medio de una URL en el par\u00e1metro (1) db_conf o (2) ADODB_DIR en el archivo utils/stphpimage_show.php; o una URL en el par\u00e1metro STPHPLIB_DIR en el archivo (3) stphpbutton.php,(4) stphpcheckbox.php,(5) stphpcheckboxwithcaption.php,(6) stphpcheckgroup.php,(7) stphpcomponent.php,(8) stphpcontrolwithcaption.php,(9) stphpedit.php, (10) stphpeditwithcaption.php, (11) stphphr.php, (12) stphpimage.php, (13) stphpimagewithcaption.php, (14) stphplabel.php, (15) stphplistbox.php, (16) stphplistboxwithcaption.php, (17) stphplocale.php, (18) stphppanel.php, (19) stphpradiobutton.php, (20) stphpradiobuttonwithcaption.php, (21) stphpradiogroup.php, (22) stphprichbutton.php, (23) stphpspacer.php, (24) esptosible.php, (25) stphptablecell.php, (26) stphptablerow.php, (27) stphptabpanel.php, (28) stphptabtitle.php, (29) stphptextarea.php, (30) stphptextareawithcaption.php, (31) stphptoolbar.php, (32) stphpwindow.php, (33) stphpxmldoc.php, o (34) stphpxmlelement.php, un conjunto diferente de vectores de ataque de CVE-2007-4737. NOTA: la procedencia de esta informaci\u00f3n es desconocida; los datos son obtenidos \u00fanicamente de la informaci\u00f3n de terceros." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "baseScore": 7.5, "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL" }, "baseSeverity": "HIGH", "exploitabilityScore": 10.0, "impactScore": 6.4, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": true, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-20" }, { "lang": "en", "value": "CWE-94" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:speedtech:stphplibrary:0.8.0:*:*:*:*:*:*:*", "matchCriteriaId": "8E05F402-C6FD-4C3C-B7A5-BC9AADA1FF78" } ] } ] } ], "references": [ { "url": "http://osvdb.org/39073", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39074", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39075", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39076", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39077", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39078", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39079", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39080", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39081", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39082", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39083", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39084", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39085", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39086", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39087", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39088", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39089", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39090", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39091", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39092", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39093", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39094", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39095", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39096", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39097", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39098", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39099", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39100", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39101", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39102", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39103", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39104", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39105", "source": "cve@mitre.org" }, { "url": "http://secunia.com/advisories/26658", "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ] }, { "url": "http://www.securityfocus.com/bid/25525", "source": "cve@mitre.org" }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/36417", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/39073", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39074", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39075", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39076", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39077", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39078", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39079", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39080", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39081", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39082", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39083", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39084", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39085", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39086", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39087", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39088", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39089", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39090", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39091", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39092", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39093", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39094", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39095", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39096", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39097", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39098", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39099", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39100", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39101", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39102", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39103", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39104", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/39105", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://secunia.com/advisories/26658", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "http://www.securityfocus.com/bid/25525", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/36417", "source": "af854a3a-2127-422b-91ae-364da2661108" } ] }