CVE
- Id
- 29462
- CVE No.
- CVE-2007-6105
- Status
- Candidate
- Description
- Multiple PHP remote file inclusion vulnerabilities in TalkBack 2.2.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) language_file parameter to (a) comments-display-tpl.php and (b) addons/separate-comments-mod/my-comments-display-tpl.php and the (2) config[comments_form_tpl] parameter to comments-display-tpl.php.
- Phase
- Assigned (20071123)
- Votes
- None (candidate not yet proposed)
- Comments