CVE-2007-5178
published 2007-10-03CVE-2007-5178: contrib/mx_glance_sdesc.php in the mx_glance 2.3.3 module for mxBB places a critical security check within a comment because of a missing comment delimiter…
PriorityP339medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EXPLOIT
EPSS
3.01%
85.7th percentile
contrib/mx_glance_sdesc.php in the mx_glance 2.3.3 module for mxBB places a critical security check within a comment because of a missing comment delimiter, which allows remote attackers to conduct remote file inclusion attacks and execute arbitrary PHP code via a URL in the mx_root_path parameter. NOTE: some sources incorrectly state that phpbb_root_path is the affected parameter.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mxbb | mx_glance | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
http://osvdb.org/37400http://secunia.com/advisories/27011http://www.attrition.org/pipermail/vim/2007-October/001807.htmlhttp://www.attrition.org/pipermail/vim/2007-October/001808.htmlhttp://www.securityfocus.com/bid/25866http://www.vupen.com/english/advisories/2007/3326https://exchange.xforce.ibmcloud.com/vulnerabilities/36867https://www.exploit-db.com/exploits/4470http://osvdb.org/37400http://secunia.com/advisories/27011http://www.attrition.org/pipermail/vim/2007-October/001807.htmlhttp://www.attrition.org/pipermail/vim/2007-October/001808.htmlhttp://www.securityfocus.com/bid/25866http://www.vupen.com/english/advisories/2007/3326https://exchange.xforce.ibmcloud.com/vulnerabilities/36867https://www.exploit-db.com/exploits/4470
2007-10-03
Published