CVE-2007-0499

Sangwan KIM Phpindexpage < 1.0.1 - Code Injection

Title source: rule

Description

PHP remote file inclusion vulnerability in config.php in Sangwan Kim phpIndexPage 1.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the env[inc_path] parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by DeltahackingTEAM · perlwebappsphp
https://www.exploit-db.com/exploits/3164

Scores

EPSS 0.0687
EPSS Percentile 91.4%

Details

CWE
CWE-94
Status published
Products (1)
sangwan_kim/phpindexpage < 1.0.1
Published Jan 25, 2007
Tracked Since Feb 18, 2026