Multiple PHP remote file inclusion vulnerabilities in SunLight CMS 5.3 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) _connect.php or (2) modules/startup.php.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 06 Feb 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sunlight-cms
Sunlight-cms sunlight Cms |
|
| CPEs | cpe:2.3:a:sunlight-cms:sunlight_cms:5.3:*:*:*:*:*:*:* | |
| Vendors & Products |
Sunlight Cms
Sunlight Cms sunlight Cms |
Sunlight-cms
Sunlight-cms sunlight Cms |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T13:49:57.380Z
Reserved: 2007-05-21T00:00:00
Link: CVE-2007-2774
No data.
Status : Analyzed
Published: 2007-05-21T23:30:00.000
Modified: 2026-02-06T20:55:16.183
Link: CVE-2007-2774
No data.
OpenCVE Enrichment
No data.
Weaknesses