7.5
CVSSv2

CVE-2009-1781

Published: 22/05/2009 Updated: 20/05/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Static code injection vulnerability in admin.php in Frax.dk Php Recommend 1.3 and previous versions allows remote malicious users to inject arbitrary PHP code into phpre_config.php via the form_aula parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

frax php recommend

Exploits

Php Recommend <=13 Authentication Bypass/Remote File Include/Code Injection Exploits Author: scriptjunkie scriptjunkie1 {nospam} googlemail {nospam} com Condition: RFI: allow_url_fopen = On code injection: magic_quotes_gpc = Off Exploits: Authentication Bypass: change admin username and password: vulnerablecom/adminphp?submit=submit&amp ...