{ "schema_version": "1.4.0", "id": "GHSA-g2x7-2429-c3m5", "modified": "2022-05-01T17:58:56Z", "published": "2022-05-01T17:58:56Z", "aliases": [ "CVE-2007-1987" ], "details": "** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in PHPEcho CMS 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) _plugin_file parameter to smarty/internals/core.load_pulgins.php or the (2) root_path parameter to index.php. NOTE: CVE disputes (1) because the inclusion occurs within a function that is not called during a direct request. CVE disputes (2) because root_path is defined in config.php before use.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2007-1987" }, { "type": "WEB", "url": "http://osvdb.org/34117" }, { "type": "WEB", "url": "http://securityreason.com/securityalert/2551" }, { "type": "WEB", "url": "http://www.securityfocus.com/archive/1/464709/100/0/threaded" } ], "database_specific": { "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2007-04-12T01:19:00Z" } }