CVE-2007-0863

PHP remote file inclusion vulnerability in Trevorchan 0.7 and earlier allows remote attackers to execute arbitrary code via the tc_config[rootdir] parameter to (1) upgrade.php, (2) paint_save.php, (3) menu.php, (4) manage.php, and (5) banned.php. NOTE: his issue has been disputed by reliable third parties, who state that the variable is set before use in config.php
Configurations

Configuration 1 (hide)

cpe:2.3:a:trevorchan:trevorchan:*:*:*:*:*:*:*:*

History

07 Nov 2023, 02:00

Type Values Removed Values Added
Summary ** DISPUTED ** PHP remote file inclusion vulnerability in Trevorchan 0.7 and earlier allows remote attackers to execute arbitrary code via the tc_config[rootdir] parameter to (1) upgrade.php, (2) paint_save.php, (3) menu.php, (4) manage.php, and (5) banned.php. NOTE: his issue has been disputed by reliable third parties, who state that the variable is set before use in config.php. PHP remote file inclusion vulnerability in Trevorchan 0.7 and earlier allows remote attackers to execute arbitrary code via the tc_config[rootdir] parameter to (1) upgrade.php, (2) paint_save.php, (3) menu.php, (4) manage.php, and (5) banned.php. NOTE: his issue has been disputed by reliable third parties, who state that the variable is set before use in config.php

Information

Published : 2007-02-09 01:28

Updated : 2024-05-17 00:32


NVD link : CVE-2007-0863

Mitre link : CVE-2007-0863

CVE.ORG link : CVE-2007-0863


JSON object : View

Products Affected

trevorchan

  • trevorchan