10
CVE-2007-1394
- EPSS 4.29%
- Veröffentlicht 10.03.2007 22:19:00
- Zuletzt bearbeitet 16.06.2026 22:37:30
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Direct static code injection vulnerability in startsession.php in Flat Chat 2.0 allows remote attackers to execute arbitrary PHP code via the Chat Name field, which is inserted into online.txt and included by users.php. NOTE: some of these details are obtained from third party information.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.29% | 0.898 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
http://osvdb.org/33890
http://secunia.com/advisories/24433
http://www.securityfocus.com/bid/22865
http://www.vupen.com/english/advisories/2007/0871
https://exchange.xforce.ibmcloud.com/vulnerabilities/32882
https://www.exploit-db.com/exploits/3428