Unrated severityNVD Advisory· Published Aug 14, 2007· Updated Apr 23, 2026
CVE-2007-4328
CVE-2007-4328
Description
Multiple PHP remote file inclusion vulnerabilities in Mapos Bilder Galerie 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter to (1) index.php, (2) galerie.php, or (3) anzagien.php. NOTE: A later report states that 1.1 is also affected, but that the filename for vector 3 is anzeigen.php.
Affected products
2cpe:2.3:a:mapos_scripts:bilder_galerie:1.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:mapos_scripts:bilder_galerie:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:mapos_scripts:bilder_galerie:1.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- www.securityfocus.com/bid/25256nvdExploit
- secunia.com/advisories/26400nvdVendor Advisory
- www.vupen.com/english/advisories/2007/2838nvdVendor Advisory
- osvdb.org/36455nvd
- osvdb.org/36456nvd
- osvdb.org/36457nvd
- securityreason.com/securityalert/2999nvd
- www.securityfocus.com/archive/1/475952/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/35923nvd
News mentions
0No linked articles in our index yet.