关键漏洞信息 漏洞类型: Remote File Inclusion Vulnerability 影响版本: MySQL Commander <= 2.7 CVE ID: CVE-2007-1439 CWE ID: CWE-89 CVSS Base Score: 9.3/10 Risk: High 影响评估 远程: Yes 本地: No Impact Subscore: 10/10 - Attack complexity: Medium - Confidentiality impact: Complete - Integrity impact: Complete - Availability impact: Complete Exploitability Subscore: 8.6/10 - Authentication: No required 漏洞描述 受影响软件: MySQL Commander 版本: <= 2.7 漏洞详情: Invalid include function at ressourcen/dbopen.php 攻击细节: When is on and is enabled, an attacker can exploit this vulnerability with a simple PHP injection script. 利用示例 解决方案 Sanitize variable on the affected file. Turn off .