Critical Vulnerability Information Vulnerability Type: Remote File Inclusion Vulnerability Affected Versions: MySQL Commander <= 2.7 CVE ID: CVE-2007-1439 CWE ID: CWE-89 CVSS Base Score: 9.3/10 Risk: High Impact Assessment Remote: Yes Local: No Impact Subscore: 10/10 - Attack complexity: Medium - Confidentiality impact: Complete - Integrity impact: Complete - Availability impact: Complete Exploitability Subscore: 8.6/10 - Authentication: No required Vulnerability Description Affected Software: MySQL Commander Version: <= 2.7 Vulnerability Details: Invalid include function at ressourcen/dbopen.php Attack Details: When is enabled and is turned on, an attacker can exploit this vulnerability using a simple PHP injection script. Exploit Example Solution Sanitize the variable in the affected file. Disable .