CVE-2007-5138 describes a remote file inclusion vulnerability in lustig.cms BETA 2.5, specifically within the forum/forum.php component. An attacker can exploit this by injecting a malicious URL into the 'view' parameter, leading to arbitrary PHP code execution on the affected server. While not actively exploited in the wild and lacking Metasploit/Nuclei modules, public exploit code exists on ExploitDB, indicating a clear path for exploitation. The vulnerability carries a CVSS score of 6.8, signifying moderate severity with potential for partial confidentiality, integrity, and availability impact, yet it has garnered minimal community discussion or media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.5_betaCPE matchmatch criteria | cpe:2.3:a:lustig:lustig.cms:2.5_beta:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.