Phpmyphorum · Phpmyphorum · CVE-2007-0361
Name of the Vulnerable Software and Affected Versions:
PHPMyphorum version 1.5a
Description:
The issue allows remote attackers to execute arbitrary PHP code via a URL in the `chem` parameter in the mep/frame.php file.
Recommendations:
For PHPMyphorum version 1.5a, consider restricting access to the mep/frame.php file to minimize the risk of exploitation. Avoid using the `chem` parameter in the affected file until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.