Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including CMS Made Simple, SAPID CMF, Journalness, PacerCMS, and Open-Realty, allows remote attackers to execute arbitrary code via PHP sequences in the last_module parameter.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2007-09-24 15:17
Updated : 2017-09-28 18:29
NVD link : CVE-2007-5056
Mitre link : CVE-2007-5056
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
open-realty
- open-realty
pacercms
- pacercms
adodb_lite
- adodb_lite
sapid
- sapid_cmf
journalness
- journalness
cmsmadesimple
- cms_made_simple