CVE-2009-3660

EUVD-2009-3635
PHP remote file inclusion vulnerability in libraries/database.php in Efront 3.5.4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.  NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's security documentation.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
Affected Products (NVD)
VendorProductVersion
efrontlearningefront
𝑥
≤ 3.5.4
efrontlearningefront
3.1.0
efrontlearningefront
3.1.2
efrontlearningefront
3.1.3
efrontlearningefront
3.1.4
efrontlearningefront
3.5.0
efrontlearningefront
3.5.0:beta1
efrontlearningefront
3.5.0:beta2
efrontlearningefront
3.5.0:beta3
efrontlearningefront
3.5.0:beta4
efrontlearningefront
3.5.1
𝑥
= Vulnerable software versions