CVE-2007-0172

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/01/2007
Last modified:
09/04/2025

Description

Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.3.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the AMG_serverpath parameter to (1) comments.php and (2) signin.php; and possibly via a URL in unspecified parameters to (3) include/submit.inc.php, (4) admin/index.php, (5) include/cm_submit.inc.php, and (6) index.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:allmyguests_project:allmyguests:*:*:*:*:*:*:*:* 0.3 (including)