{ "schema_version": "1.4.0", "id": "GHSA-gq2c-rqg7-fr3g", "modified": "2022-05-01T18:01:06Z", "published": "2022-05-01T18:01:06Z", "aliases": [ "CVE-2007-2185" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Supasite 1.23b allow remote attackers to execute arbitrary PHP code via a URL in the supa[db_path] parameter to (1) common_functions.php, (2) admin_auth_cookies.php, (3) admin_mods.php, (4) admin_news.php, (5) admin_topics.php, (6) admin_users.php, (7) admin_utilities.php, (8) site_comment.php, or (9) site_news.php; or the supa[include_path] parameter to (10) admin_settings.php or (11) backend_site.php.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2007-2185" }, { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/33796" }, { "type": "WEB", "url": "https://www.exploit-db.com/exploits/3771" }, { "type": "WEB", "url": "http://osvdb.org/38845" }, { "type": "WEB", "url": "http://osvdb.org/38846" }, { "type": "WEB", "url": "http://osvdb.org/38847" }, { "type": "WEB", "url": "http://osvdb.org/38848" }, { "type": "WEB", "url": "http://osvdb.org/38849" }, { "type": "WEB", "url": "http://osvdb.org/38850" }, { "type": "WEB", "url": "http://osvdb.org/38851" }, { "type": "WEB", "url": "http://osvdb.org/38852" }, { "type": "WEB", "url": "http://osvdb.org/38853" }, { "type": "WEB", "url": "http://osvdb.org/38854" }, { "type": "WEB", "url": "http://osvdb.org/38855" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/23581" }, { "type": "WEB", "url": "http://www.vupen.com/english/advisories/2007/1492" } ], "database_specific": { "cwe_ids": [ "CWE-94" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2007-04-24T17:19:00Z" } }