CVE-2007-0804

GGCMS 1.1.0 RC1 and earlier - Directory Traversal and Arbitrary PHP Code Injection via subpageName Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-0804. PoCs published by Kacper.

AI-analyzed exploit summary This exploit targets a file write vulnerability in GGCMS <= v1.1.0 RC1, allowing arbitrary file overwrite via the 'subpageName' parameter in admin/subpages.php. It supports both remote defacement and remote code execution by injecting malicious content into template files.

Description

Directory traversal vulnerability in admin/subpages.php in GGCMS 1.1.0 RC1 and earlier allows remote attackers to inject arbitrary PHP code into arbitrary files via ".." sequences in the subpageName parameter, as demonstrated by injecting PHP code into a template file.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Kacper · phpwebappsphp
https://www.exploit-db.com/exploits/3271

This exploit targets a file write vulnerability in GGCMS <= v1.1.0 RC1, allowing arbitrary file overwrite via the 'subpageName' parameter in admin/subpages.php. It supports both remote defacement and remote code execution by injecting malicious content into template files.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: GGCMS v1.1.0 RC1
Auth required
Prerequisites: Access to admin/subpages.php · Valid authentication credentials
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/0492
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/32211
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/22412
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/3271
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/35849

Scores

EPSS 0.0242
EPSS Percentile 82.0%

Details

Status published
Products (1)
ggcms/ggcms 1.1.0_rc1
Published Feb 07, 2007
Tracked Since Feb 18, 2026