Description
Multiple PHP remote file inclusion vulnerabilities in Modules Builder (modbuild) 4.1 for Comdev One Admin allow remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter to (1) config-bak.php or (2) config.php. NOTE: CVE disputes this vulnerability because the unmodified scripts set the applicable variable to the empty string; reasonable modified copies would use a fixed pathname string
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 17 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-17T14:37:36.145Z
Reserved: 2007-05-01T00:00:00.000Z
Link: CVE-2007-2422
Updated: 2024-08-07T13:33:29.093Z
Status : Deferred
Published: 2007-05-02T00:19:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2007-2422
No data.
OpenCVE Enrichment
No data.
Weaknesses