Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Theviper-Hacker

#36566of 53,630
7.5Total CVSS
Vulnerabilities · 1
PT-2007-1832
7.5
2007-01-19
Phpmyphorum · Phpmyphorum · CVE-2007-0361
Name of the Vulnerable Software and Affected Versions: PHPMyphorum version 1.5a Description: The issue allows remote attackers to execute arbitrary PHP code via a URL in the `chem` parameter in the mep/frame.php file. Recommendations: For PHPMyphorum version 1.5a, consider restricting access to the mep/frame.php file to minimize the risk of exploitation. Avoid using the `chem` parameter in the affected file until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.