Remote File Inclusion Vulnerability in ISS Proventia Network IPS
CVE-2007-3831

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
17 July 2007

Badges

👾 Exploit Exists🟡 Public PoC

Summary

The ISS Proventia Network IPS configurations in versions GX5108 1.3 and GX5008 1.5 are susceptible to a remote file inclusion flaw, specifically in the main.php file. This vulnerability enables attackers to execute arbitrary PHP code by manipulating the page parameter with a crafted URL, potentially compromising the integrity and security of the affected systems. Proper mitigation steps include updating to the latest software versions and configuring security settings to protect against unauthorized URL inclusions.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

EPSS Score

5% chance of being exploited in the next 30 days.

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.