CVE-2007-0986

Jupiter CMS <1.1.5 - RCE

Title source: llm

Description

PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5, when PHP 5.0.0 or later is used, allows remote attackers to execute arbitrary PHP code via an ftp URL in the n parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by DarkFig · textwebappsphp
https://www.exploit-db.com/exploits/3309

Scores

EPSS 0.1142
EPSS Percentile 93.5%

Classification

CWE
CWE-94
Status draft

Affected Products (1)

jupiter_cms/jupiter_cms

Timeline

Published Feb 16, 2007
Tracked Since Feb 18, 2026