PT-2007-3282 · Scorp · Scorp Book

Dj7Xpl

·

Published

2007-04-10

·

Updated

2018-10-16

·

CVE-2007-1937

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Scorp Book version 1.0
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the config parameter in the smilies.php file.
Recommendations For Scorp Book version 1.0, consider restricting access to the smilies.php file and avoid using the config parameter until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1937

Affected Products

Scorp Book