CVE-2007-5600

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
19/10/2007
Last modified:
09/04/2025

Description

Incomplete blacklist vulnerability in index.php in Artmedic CMS 3.4 and earlier allows remote attackers to execute arbitrary PHP code via a (1) UNC share pathname, or a (2) ftps, (3) ssh2.sftp, or (4) ssh2.scp URL, in the page parameter, for which PHP remote file inclusion is blocked only for http, https, and ftp URLs.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:artmedic_webdesign:artmedic_cms:*:*:*:*:*:*:*:* 3.4 (including)