← back
CVE-2007-2148

CVE-2007-2148

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 2.0%
from disclosure to weapon0 days
Published on NVDApr 19
1st PoCApr 12
exploitation probability
2.0%top 21% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Direct static code injection vulnerability in admin/save.php in Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier allows remote authenticated administrators to inject PHP code into .html files via the html parameter, as demonstrated by head.html and foot.html, which are included and executed upon a direct request for index.php. NOTE: a separate vulnerability could be leveraged to make this issue exploitable by remote unauthenticated attackers.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.