CVE-2007-1233

STWC-Counter <3.4.0.0 - RCE

Title source: llm

Description

PHP remote file inclusion vulnerability in downloadcounter.php in STWC-Counter 3.4.0.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the stwc_counter_verzeichniss parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by burncycle · phpwebappsphp
https://www.exploit-db.com/exploits/3379

Scores

EPSS 0.1169
EPSS Percentile 93.7%

Details

CWE
CWE-94
Status published
Products (48)
stwc-counter/stwc-counter 1.01
stwc-counter/stwc-counter 1.1
stwc-counter/stwc-counter 1.2
stwc-counter/stwc-counter 1.02
stwc-counter/stwc-counter 1.11
stwc-counter/stwc-counter 1.12
stwc-counter/stwc-counter 1.21
stwc-counter/stwc-counter 1.22
stwc-counter/stwc-counter 2.0.0
stwc-counter/stwc-counter 2.0.1
... and 38 more
Published Mar 03, 2007
Tracked Since Feb 18, 2026