CVE-2007-1635
HIGH 9.0EPSS 2.8%
Static code injection vulnerability in admin/settings.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote authenticated users to inject arbitrary PHP code via the xtop parameter in a "ConfigSave" op to admin.php, which can later be accessed via a "Configure" op to admin.php.
- CVSS v2.0
- 9.0 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C - EPSS
- 2.78% chance of exploitation in the next 30 days, 85th percentile
- Published
- 2007-03-23
- Updated
- 2024-08-07