Franklin Huang · Franklin Huang Flip · CVE-2007-2140
**Name of the Vulnerable Software and Affected Versions**
Franklin Huang Flip (aka Flip-search-add-on) version 2.0
**Description**
The issue allows remote attackers to execute arbitrary PHP code via a URL in the `incpath` parameter. This can be achieved by manipulating the API endpoint, although the specific endpoint is not mentioned. The estimated number of potentially affected devices and details about real-world incidents are not provided.
**Recommendations**
For Franklin Huang Flip (aka Flip-search-add-on) version 2.0, consider restricting access to the `incpath` parameter to minimize the risk of exploitation. Avoid using the `incpath` parameter in affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.