CVE Vulnerabilities

CVE-2007-2001

Published: Apr 12, 2007 | Modified: Oct 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple direct static code injection vulnerabilities in admin/configurer2.php in Crea-Book 1.0 and earlier allow remote authenticated administrators to execute arbitrary PHP code via the Fond de la page (background color) field and other unspecified fields, which injects into config.inc.php3.

Affected Software

Name Vendor Start Version End Version
Crea-book Crea-book * 1.0 (including)

References