Back

CRITICAL

PHP remote file inclusion vulnerability in centipaid_class.php in CentiPaid 1.4.3 allows remote attackers to execute arbitrary code via a URL in the class_pwd parameter

Published Feb 8, 2007

Description

PHP remote file inclusion vulnerability in centipaid_class.php in CentiPaid 1.4.3 allows remote attackers to execute arbitrary code via a URL in the class_pwd parameter. NOTE: this issue has been disputed by CVE and multiple third parties, who state that $class_pwd is set to a static value before the relevant include statement

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 8, 2007
Updated Jan 17, 2025
Reserved Feb 8, 2007
CISA Vulnrichment
Updated Jan 17, 2025
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a