4.3
CVE-2007-2670
- EPSS 1.23%
- Veröffentlicht 14.05.2007 23:19:00
- Zuletzt bearbeitet 16.06.2026 22:40:04
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
PHPChain 1.0 and earlier allows remote attackers to obtain the installation path via invalid values of the catid parameter to (1) settings.php or (2) cat.php, as demonstrated by XSS manipulations.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Globalmegacorp ≫ Phpchain Version <= 1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.23% | 0.651 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
http://pridels0.blogspot.com/2007/05/phpchain-vuln.html
http://secunia.com/advisories/25128
http://www.securityfocus.com/bid/23761
http://www.vupen.com/english/advisories/2007/1647
http://osvdb.org/35538
https://exchange.xforce.ibmcloud.com/vulnerabilities/34019