{ "schema_version": "1.4.0", "id": "GHSA-x5fh-w6pw-cff3", "modified": "2022-05-01T18:26:35Z", "published": "2022-05-01T18:26:35Z", "aliases": [ "CVE-2007-4738" ], "details": "Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) db_conf or (2) ADODB_DIR parameter to utils/stphpimage_show.php; or a URL in the STPHPLIB_DIR parameter to (3) stphpbutton.php, (4) stphpcheckbox.php, (5) stphpcheckboxwithcaption.php, (6) stphpcheckgroup.php, (7) stphpcomponent.php, (8) stphpcontrolwithcaption.php, (9) stphpedit.php, (10) stphpeditwithcaption.php, (11) stphphr.php, (12) stphpimage.php, (13) stphpimagewithcaption.php, (14) stphplabel.php, (15) stphplistbox.php, (16) stphplistboxwithcaption.php, (17) stphplocale.php, (18) stphppanel.php, (19) stphpradiobutton.php, (20) stphpradiobuttonwithcaption.php, (21) stphpradiogroup.php, (22) stphprichbutton.php, (23) stphpspacer.php, (24) stphptable.php, (25) stphptablecell.php, (26) stphptablerow.php, (27) stphptabpanel.php, (28) stphptabtitle.php, (29) stphptextarea.php, (30) stphptextareawithcaption.php, (31) stphptoolbar.php, (32) stphpwindow.php, (33) stphpxmldoc.php, or (34) stphpxmlelement.php, a different set of vectors than CVE-2007-4737. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2007-4738" }, { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/36417" }, { "type": "WEB", "url": "http://osvdb.org/39073" }, { "type": "WEB", "url": "http://osvdb.org/39074" }, { "type": "WEB", "url": "http://osvdb.org/39075" }, { "type": "WEB", "url": "http://osvdb.org/39076" }, { "type": "WEB", "url": "http://osvdb.org/39077" }, { "type": "WEB", "url": "http://osvdb.org/39078" }, { "type": "WEB", "url": "http://osvdb.org/39079" }, { "type": "WEB", "url": "http://osvdb.org/39080" }, { "type": "WEB", "url": "http://osvdb.org/39081" }, { "type": "WEB", "url": "http://osvdb.org/39082" }, { "type": "WEB", "url": "http://osvdb.org/39083" }, { "type": "WEB", "url": "http://osvdb.org/39084" }, { "type": "WEB", "url": "http://osvdb.org/39085" }, { "type": "WEB", "url": "http://osvdb.org/39086" }, { "type": "WEB", "url": "http://osvdb.org/39087" }, { "type": "WEB", "url": "http://osvdb.org/39088" }, { "type": "WEB", "url": "http://osvdb.org/39089" }, { "type": "WEB", "url": "http://osvdb.org/39090" }, { "type": "WEB", "url": "http://osvdb.org/39091" }, { "type": "WEB", "url": "http://osvdb.org/39092" }, { "type": "WEB", "url": "http://osvdb.org/39093" }, { "type": "WEB", "url": "http://osvdb.org/39094" }, { "type": "WEB", "url": "http://osvdb.org/39095" }, { "type": "WEB", "url": "http://osvdb.org/39096" }, { "type": "WEB", "url": "http://osvdb.org/39097" }, { "type": "WEB", "url": "http://osvdb.org/39098" }, { "type": "WEB", "url": "http://osvdb.org/39099" }, { "type": "WEB", "url": "http://osvdb.org/39100" }, { "type": "WEB", "url": "http://osvdb.org/39101" }, { "type": "WEB", "url": "http://osvdb.org/39102" }, { "type": "WEB", "url": "http://osvdb.org/39103" }, { "type": "WEB", "url": "http://osvdb.org/39104" }, { "type": "WEB", "url": "http://osvdb.org/39105" }, { "type": "WEB", "url": "http://secunia.com/advisories/26658" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/25525" } ], "database_specific": { "cwe_ids": [ "CWE-20", "CWE-94" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2007-09-06T19:17:00Z" } }