Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2007-5294

EPSS 6.87% · P91
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2007-5294

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
PHP remote file inclusion vulnerability in core/aural.php in IDMOS 1.0-beta (aka Phoenix) allows remote attackers to execute arbitrary PHP code via a URL in the site_absolute_path parameter.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
IDMOS 'aural.php' PHP远程文件包含漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
IDMOS 1.0-beta (又称Phoenix)版本中core/aural.php存在PHP远程文件包含漏洞,远程攻击者可以借助site_absolute_path参数中的一个URL执行任意PHP代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2007-5294

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2007-5294

登录查看更多情报信息。

Same Patch Batch · n/a · 2007-10-09 · 63 CVEs total

CVE-2007-5308PHP Homepage M 'galerie.php' SQL注入漏洞
CVE-2007-3897Microsoft Outlook Express和Windows Mail NNTP协议回应数据缓冲区错误漏洞
CVE-2007-5319Sun Solaris vuidmice STREAMS模数未明拒绝服务漏洞
CVE-2007-4466Electronic Arts SnoopyCtrl ActiveX控件'NPSnpy.dll' 多个缓冲区溢出漏洞
CVE-2007-3899Microsoft Word工作区内存破坏远程代码执行漏洞
CVE-2007-5313Picturesolution 'Config.PHP' 远程文件包含漏洞
CVE-2007-5312TorrentTrader Classic cat参数多个跨站脚本攻击漏洞
CVE-2007-5311TorrentTrader Classic Edition 'backend/admin-functions.php' 目录遍历漏洞
CVE-2007-5310Joomla! Webmaster-Tips.net 'admin.wmtportfolio.php' 远程文件包含漏洞
CVE-2007-5309Joomla! Webmaster-Tips.net Flash Image Gallery 'admin.wmtgallery.php' 远程文件包含漏洞
CVE-2007-5314XKiosk WEB 'xkurl.php' 代码注入漏洞
CVE-2007-5307ELSEIF CMS 'upload.php' alphanumeric参数多个输入验证漏洞
CVE-2007-5306ELSEIF CMS 'votesresultats.php' 多个输入验证漏洞
CVE-2007-5305Else If CMS 多个PHP远程文件包含漏洞
CVE-2007-5304ELSEIF CMS 跨站脚本攻击漏洞
CVE-2007-5303SnewsCMS Rus 'news_page.php' 跨站脚本攻击漏洞
CVE-2007-5302HP System Management Homepage (SMH) for Linux, Windows, and HP-UX 多个跨站脚本攻击漏洞
CVE-2007-5301AlsaPlayer Vorbis输入插件OGG文件处理远程缓冲区溢出漏洞
CVE-2007-5300wzdftpd USER指令远程拒绝服务漏洞
CVE-2007-5299SkaDate Online Dating Software 'member/' 多个目录遍历漏洞

Showing top 20 of 63 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2007-5294

No comments yet


Leave a comment