mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-09 11:05:39 +02:00
18 lines
710 B
Markdown
18 lines
710 B
Markdown
### [CVE-2007-3587](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3587)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
MyCMS 0.9.8 and earlier allows remote attackers to gain privileges via the admin cookie parameter, as demonstrated by a post to admin/settings.php that injects PHP code into settings.inc, which can then be executed via a direct request to index.php.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://www.exploit-db.com/exploits/4145
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|