Variable overwrite vulnerability in groupit/base/groupit.start.inc in Groupit 2.00b5 allows remote attackers to conduct remote file inclusion attacks and execute arbitrary PHP code via arguments that are written to $_GLOBALS, as demonstrated using a URL in the c_basepath parameter to (1) content.php, (2) userprofile.php, (3) password.php, (4) dispatch.php, and (5) deliver.php in html/, and possibly (6) load.inc.php and related files.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T12:59:08.292Z
Reserved: 2007-03-16T00:00:00
Link: CVE-2007-1472
No data.
Status : Deferred
Published: 2007-03-16T21:19:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2007-1472
No data.
OpenCVE Enrichment
No data.
Weaknesses