VYPR

Mospray

by Canebluem

CVEs (1)

  • CVE-2006-3847Jul 25, 2006
    risk 0.04cvss epss 0.17

    PHP remote file inclusion vulnerability in (1) admin.php, and possibly (2) details.php, (3) modify.php, (4) newgroup.php, (5) newtask.php, and (6) rss.php, in MoSpray (aka com_mospray) 1.8 RC1 allows remote attackers to execute arbitrary PHP code via a URL in the basedir parameter.