RSS   Vulnerabilities for 'Actsite'   RSS

2007-10-03
 
CVE-2007-5175

 

 
PHP remote file inclusion vulnerability lib/base.php in actSite 1.991 Beta allows remote attackers to execute arbitrary PHP code via a URL in the BaseCfg[BaseDir] parameter.

 
 
CVE-2007-5174

CWE-22
 

 
Directory traversal vulnerability in phpinc/news.php in actSite 1.56 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the do parameter.

 


Copyright 2017, cxsecurity.com

 

Back to Top