{ "schema_version": "1.4.0", "id": "GHSA-cvp9-hwc6-x9xf", "modified": "2025-04-09T03:46:20Z", "published": "2022-05-01T18:28:34Z", "aliases": [ "CVE-2007-4948" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Webmedia Explorer (webmex) 3.2.2 allow remote attackers to execute arbitrary PHP code via (1) a URL in the path_include parameter to includes/rss.class.php, (2) a URL in the path_template parameter to (a) templates/main.tpl.php or (b) templates/folder_messages_link_message_name.tpl.php, or (4) a URL in the path_templates parameter to templates/sidebar.tpl.php. NOTE: the vulnerability is present only when the administrator does not follow installation instructions about the requirement for .htaccess support. NOTE: the includes/core.lib.php vector is already covered by CVE-2006-5252.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2007-4948" }, { "type": "WEB", "url": "http://arfis.wordpress.com/2007/09/14/rfi-03-webmedia-explorer" }, { "type": "WEB", "url": "http://osvdb.org/43140" }, { "type": "WEB", "url": "http://osvdb.org/43141" }, { "type": "WEB", "url": "http://osvdb.org/43142" }, { "type": "WEB", "url": "http://osvdb.org/43143" } ], "database_specific": { "cwe_ids": [ "CWE-94" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2007-09-18T20:17:00Z" } }