CVE-2007-2199

PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vincent Blavet PhpConcept Library, as used in multiple products including (1) Joomla! 1.5.0 Beta, (2) N/X Web Content Management System (WCMS) 4.5, (3) CJG EXPLORER PRO 3.3, and (4) phpSiteBackup 0.1, allows remote attackers to execute arbitrary PHP code via a URL in the g_pcltar_lib_dir parameter.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cjg_explorer_pro:cjg_explorer_pro:3.3:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5.0:beta:*:*:*:*:*:*
cpe:2.3:a:nx:n_x_wcms:4.5:*:*:*:*:*:*:*
cpe:2.3:a:phpsitebackup:phpsitebackup:0.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2007-04-24 20:19

Updated : 2023-12-10 10:40


NVD link : CVE-2007-2199

Mitre link : CVE-2007-2199

CVE.ORG link : CVE-2007-2199


JSON object : View

Products Affected

nx

  • n_x_wcms

cjg_explorer_pro

  • cjg_explorer_pro

phpsitebackup

  • phpsitebackup

joomla

  • joomla
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')