VulnerabilityModified
CVE-2007-1998
Direct static code injection vulnerability in HIOX Guest Book (HGB) 4.0 allows remote attackers to inject arbitrary PHP code via the Email field, which results in code execution through a direct request to gb.php.
HIGH 7.5EPSS 8.75%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (8.75%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Direct static code injection vulnerability in HIOX Guest Book (HGB) 4.0 allows remote attackers to inject arbitrary PHP code via the Email field, which results in code execution through a direct request to gb.php.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 8.75% probability · 95th percentile
- CISA KEV
- Not listed
- Affected
- hiox india/guest book
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/24835
- http://www.vupen.com/english/advisories/2007/1333
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33540
- https://www.exploit-db.com/exploits/3697
- http://secunia.com/advisories/24835
- http://www.vupen.com/english/advisories/2007/1333
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33540
- https://www.exploit-db.com/exploits/3697
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.