ID

VAR-200705-0355


CVE

CVE-2007-2736


TITLE

Achievo of index.php In PHP Remote file inclusion vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2007-002038

DESCRIPTION

PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config_atkroot parameter. Achievo is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data. Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible. Achievo 1.1.0 is vulnerable to this issue; other versions may also be affected

Trust: 1.98

sources: NVD: CVE-2007-2736 // JVNDB: JVNDB-2007-002038 // BID: 23992 // VULHUB: VHN-26098

AFFECTED PRODUCTS

vendor:achievomodel:achievoscope:eqversion:1.1.0

Trust: 1.8

vendor:microsoftmodel:windows ntscope:eqversion:4.0

Trust: 0.6

vendor:microsoftmodel:windows 98sescope: - version: -

Trust: 0.6

vendor:microsoftmodel:windows 95scope: - version: -

Trust: 0.6

vendor:microsoftmodel:windows 98scope:eqversion:gold

Trust: 0.6

vendor:achievomodel:achievoscope:eqversion:1.1

Trust: 0.3

vendor:achievomodel:achievoscope:neversion:1.2

Trust: 0.3

sources: BID: 23992 // JVNDB: JVNDB-2007-002038 // CNNVD: CNNVD-200705-369 // NVD: CVE-2007-2736

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2007-2736
value: HIGH

Trust: 1.0

NVD: CVE-2007-2736
value: HIGH

Trust: 0.8

CNNVD: CNNVD-200705-369
value: CRITICAL

Trust: 0.6

VULHUB: VHN-26098
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2007-2736
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-26098
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-26098 // JVNDB: JVNDB-2007-002038 // CNNVD: CNNVD-200705-369 // NVD: CVE-2007-2736

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2007-2736

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200705-369

TYPE

code injection

Trust: 0.6

sources: CNNVD: CNNVD-200705-369

CONFIGURATIONS

sources: JVNDB: JVNDB-2007-002038

PATCH

title:Top Pageurl:http://www.achievo.org/

Trust: 0.8

sources: JVNDB: JVNDB-2007-002038

EXTERNAL IDS

db:NVDid:CVE-2007-2736

Trust: 2.8

db:BIDid:23992

Trust: 2.0

db:OSVDBid:37919

Trust: 1.7

db:EXPLOIT-DBid:3928

Trust: 1.7

db:JVNDBid:JVNDB-2007-002038

Trust: 0.8

db:XFid:34305

Trust: 0.6

db:MILW0RMid:3928

Trust: 0.6

db:CNNVDid:CNNVD-200705-369

Trust: 0.6

db:VULHUBid:VHN-26098

Trust: 0.1

sources: VULHUB: VHN-26098 // BID: 23992 // JVNDB: JVNDB-2007-002038 // CNNVD: CNNVD-200705-369 // NVD: CVE-2007-2736

REFERENCES

url:http://www.securityfocus.com/bid/23992

Trust: 1.7

url:http://osvdb.org/37919

Trust: 1.7

url:https://www.exploit-db.com/exploits/3928

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/34305

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2007-2736

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2007-2736

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/34305

Trust: 0.6

url:http://www.milw0rm.com/exploits/3928

Trust: 0.6

url:http://www.achievo.org/

Trust: 0.3

sources: VULHUB: VHN-26098 // BID: 23992 // JVNDB: JVNDB-2007-002038 // CNNVD: CNNVD-200705-369 // NVD: CVE-2007-2736

CREDITS

Katatafish is credited with the discovery of this vulnerability.

Trust: 0.9

sources: BID: 23992 // CNNVD: CNNVD-200705-369

SOURCES

db:VULHUBid:VHN-26098
db:BIDid:23992
db:JVNDBid:JVNDB-2007-002038
db:CNNVDid:CNNVD-200705-369
db:NVDid:CVE-2007-2736

LAST UPDATE DATE

2024-11-23T23:13:19.386000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-26098date:2017-10-11T00:00:00
db:BIDid:23992date:2015-05-07T17:39:00
db:JVNDBid:JVNDB-2007-002038date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200705-369date:2007-05-22T00:00:00
db:NVDid:CVE-2007-2736date:2024-11-21T00:31:31.847

SOURCES RELEASE DATE

db:VULHUBid:VHN-26098date:2007-05-17T00:00:00
db:BIDid:23992date:2007-05-15T00:00:00
db:JVNDBid:JVNDB-2007-002038date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200705-369date:2007-05-17T00:00:00
db:NVDid:CVE-2007-2736date:2007-05-17T19:30:00