CVE-2007-4935
Summary
| CVE | CVE-2007-4935 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-09-18 18:17:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Multiple PHP remote file inclusion vulnerabilities in phpFFL 1.24 allow remote attackers to execute arbitrary PHP code via a URL in the PHPFFL_FILE_ROOT parameter to (1) admin.php, (2) custom_pages.php, (3) draft.php, (4) faq.php, (5) leagues.php, (6) livedraft.php, (7) login.php, (8) my_team.php, (9) profile.php, (10) signup.php, (11) statistics.php, (12) transactions.php, (13) program_files/admin/custom_pages.php, or (14) program_files/common.php. NOTE: the program_files/livedraft/admin.php and program_files/livedraft/livedraft.php vectors are covered by CVE-2007-4934. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| osvdb.org/39656 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/39657 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/39660 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/39654 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/39655 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/39653 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/39652 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| osvdb.org/39651 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/39650 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Page not found - SourceForge.net | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | |
| SourceForge.net: phpFFL - Fantasy Football League Manager: Files | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | |
| osvdb.org/39659 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/39658 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| phpFFL "PHPFFL_FILE_ROOT" File Inclusion Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| RFI (0.2): phpFFL - Fantasy Football League Manager « arfis | af854a3a-2127-422b-91ae-364da2661108 | arfis.wordpress.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.