Stwc · Stwc-Counter · CVE-2007-1233
**Name of the Vulnerable Software and Affected Versions**
STWC-Counter versions 3.4.0.0 and earlier
**Description**
The issue allows remote attackers to execute arbitrary PHP code. This is achieved via a URL in the `stwc counter verzeichniss` parameter in the downloadcounter.php file.
**Recommendations**
For versions 3.4.0.0 and earlier, consider restricting access to the downloadcounter.php file until a patch is available. As a temporary workaround, avoid using the `stwc counter verzeichniss` parameter in the affected API endpoint until the issue is resolved.