Lucene search

K
cvelistMitreCVELIST:CVE-2007-5772
HistoryNov 01, 2007 - 4:04 p.m.

CVE-2007-5772

2007-11-0116:04:00
mitre
www.cve.org

7 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

71.5%

Direct static code injection vulnerability in the download module in Flatnuke 3 allows remote authenticated administrators to inject arbitrary PHP code into a description.it.php file in a subdirectory of Download/ by saving a description and setting fneditmode to 1. NOTE: unauthenticated remote attackers can exploit this by leveraging a cookie manipulation issue.

7 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

71.5%

Related for CVELIST:CVE-2007-5772