PHP Remote File Inclusion Vulnerabilities in Softnews Media Group DataLife Engine
CVE-2007-1424

Currently unrated

Key Information:

Vendor
CVE Published:
13 March 2007

What is CVE-2007-1424?

Multiple vulnerabilities exist in the Softnews Media Group DataLife Engine that enable remote attackers to conduct unauthorized activities on affected systems. Specifically, these vulnerabilities allow attackers to exploit the root_dir parameter to execute arbitrary PHP code through crafted URLs in the init.php and Ajax/editnews.php scripts, leading to potential unauthorized control over the web application.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.