CVE-2007-4525

Source
https://cve.org/CVERecord?id=CVE-2007-4525
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2007-4525.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2007-4525
Downstream
Published
2007-08-25T00:17:00Z
Modified
2026-04-10T03:39:11.752864Z
Summary
[none]
Details

PHP remote file inclusion vulnerability in inc-calcul.php3 in SPIP 1.7.2 allows remote attackers to execute arbitrary PHP code via a URL in the squelettecache parameter, a different vector than CVE-2006-1702. NOTE: this issue has been disputed by third party researchers, stating that the squelettecache variable is initialized before use, and is only used within the scope of a function

Database specific
{
    "isDisputed": true
}
References

Affected packages