CVE-2007-5641
Summary
| CVE | CVE-2007-5641 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-10-23 21:47:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Multiple PHP remote file inclusion vulnerabilities in PHP Project Management 0.8.10 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the full_path parameter to (1) certinfo/index.php, (2) emails/index.php, (3) events/index.php, (4) fax/index.php, (5) files/index.php, (6) files/list.php, (7) groupadm/index.php, (8) history/index.php, (9) info/index.php, (10) log/index.php, (11) mail/index.php, (12) messages/index.php, (13) organizations/index.php, (14) phones/index.php, (15) presence/index.php, (16) projects/index.php, (17) projects/summary.inc.php, (18) projects/list.php, (19) reports/index.php, (20) search/index.php, (21) snf/index.php, (22) syslog/index.php, (23) tasks/searchsimilar.php, (24) tasks/index.php, (25) tasks/summary.inc.php, and (26) useradm/index.php in modules; (27) /ajax/loadsplash.php; (28) /blocks/birthday.php; (29) /blocks/events.php; and (30) /blocks/help.php. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Phppm | Php Project Management | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| osvdb.org/41931 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/41905 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| PHP Project Management <= 0.8.10 Multiple RFI / LFI Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| osvdb.org/41906 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/41907 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/41934 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| PHP Project Management Multiple Remote File Include Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| osvdb.org/41957 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/41909 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/41908 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/41910 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/41925 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/41912 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/41913 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/41927 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| PHP Project Management File Inclusion Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| osvdb.org/41914 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/41920 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/41917 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/41918 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| osvdb.org/41975 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/41928 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.