{ "schema_version": "1.4.0", "id": "GHSA-6xwr-cqxm-ch7r", "modified": "2025-04-09T03:46:44Z", "published": "2022-05-01T18:30:37Z", "aliases": [ "CVE-2007-5146" ], "details": "Multiple PHP remote file inclusion vulnerabilities in dedi-group Der Dirigent 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the dedi_path parameter to (1) inc.generate_code.php, (2) fnc.type_forms.php, or (3) fnc.type.php in backend/inc/, or (4) frontend.php or (5) backend.php in projekt01/cms/inc/; or (6) the this_dir parameter to backend/inc/class.filemanager.php. NOTE: vectors 4 and 5 are disputed by CVE because PHP encounters a fatal function-call error on a direct request for the file, before reaching the include statement.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2007-5146" }, { "type": "WEB", "url": "http://arfis.wordpress.com/2007/09/14/rfi-02-der-dirigent" }, { "type": "WEB", "url": "http://osvdb.org/45535" }, { "type": "WEB", "url": "http://osvdb.org/45536" }, { "type": "WEB", "url": "http://osvdb.org/45537" }, { "type": "WEB", "url": "http://osvdb.org/45538" }, { "type": "WEB", "url": "http://osvdb.org/45539" }, { "type": "WEB", "url": "http://osvdb.org/45540" } ], "database_specific": { "cwe_ids": [ "CWE-94" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2007-10-01T05:17:00Z" } }