CVE-2010-2132
N/A
N/A
Summary
Multiple PHP remote file inclusion vulnerabilities in Open Education System (OES) 0.1 beta allow remote attackers to execute arbitrary PHP code via a URL in the CONF_INCLUDE_PATH parameter to (1) forum/admin.php and (2) plotgraph/index.php in admin/modules/modules/, and (3) admin_user/mod_admuser.php and (4) ogroup/mod_group.php in admin/modules/user_account/, different vectors than CVE-2007-1446.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.packetstormsecurity.com/1002-exploits/oes-rfi.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56590
- http://www.securityfocus.com/bid/38449
References
- http://www.packetstormsecurity.com/1002-exploits/oes-rfi.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56590
- http://www.securityfocus.com/bid/38449
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.