Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Leetsecurity

#37810of 53,622
7.5Total CVSS
Vulnerabilities · 1
PT-2007-5890
7.5
2007-09-06
Stphp · Stphplibrary · CVE-2007-4737
Name of the Vulnerable Software and Affected Versions: STPHPLibrary version 0.8.0 Description: The issue allows remote attackers to execute arbitrary PHP code via a URL in the `STPHPLIB DIR` parameter to API endpoints such as "stphpapplication.php", "stphpbtnimage.php", or "stphpform.php". Recommendations: For STPHPLibrary version 0.8.0, consider restricting access to the `STPHPLIB DIR` parameter in the affected API endpoints until a patch is available. As a temporary workaround, avoid using the `STPHPLIB DIR` parameter in the "stphpapplication.php", "stphpbtnimage.php", and "stphpform.php" endpoints to minimize the risk of exploitation.