CVE-2007-1787
Last modified
CVE-2007-1787 is a vulnerability of currently unknown severity. Multiple PHP remote file inclusion vulnerabilities in lib/timesheet.class.php in Softerra Time-Assistant 6.2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) inc_dir or (2) lib_dir parameter.. EPSS estimates a 4.86% chance of exploitation in the next 30 days.
Description
Multiple PHP remote file inclusion vulnerabilities in lib/timesheet.class.php in Softerra Time-Assistant 6.2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) inc_dir or (2) lib_dir parameter.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Softerra | Time-Assistant | <= 6.2 |
References
- http://advisories.echo.or.id/adv/adv80-K-159-2007.txtVendor Advisory
- http://advisories.echo.or.id/adv/adv80-K-159-2007.txtVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-1787?
How severe is CVE-2007-1787?
How do I fix CVE-2007-1787?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-1781Minna De Office 1.x and 2.x does not properly restrict user …
- CVE-2007-1782CruiseWorks 1.09e and earlier does not properly restrict use…
- CVE-2007-1783Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2007-1784The JNILoader ActiveX control (STJNILoader.ocx) 3.1.0.26 in …
- CVE-2007-1785The RPC service in mediasvr.exe in CA BrightStor ARCserve Ba…
- CVE-2007-1786SQL injection vulnerability in Hitachi Collaboration - Onlin…
- CVE-2007-1788Flyspray 0.9.9, when output_buffering is disabled or "set to…
- CVE-2007-1789Flyspray 0.9.9 allows remote attackers to obtain sensitive i…
- CVE-2007-1790Multiple PHP remote file inclusion vulnerabilities in Kaqoo …
- CVE-2007-1791SQL injection vulnerability in wall.php in Picture-Engine 1.…
- CVE-2007-1792libdayzero.dll in the Filter Hub Service (filter-hub.exe) in…
- CVE-2007-1793SPBBCDrv.sys in Symantec Norton Personal Firewall 2006 9.1.0…
Are you affected by CVE-2007-1787?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
