CVE-2007-1525

Dayfox Blog <4 - Code Injection

Title source: llm

Description

Direct static code injection vulnerability in postpost.php in Dayfox Blog (dfblog) 4 allows remote attackers to execute arbitrary PHP code via the cat parameter, which can be executed via a request to posts.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Dj7xpl · htmlwebappsphp
https://www.exploit-db.com/exploits/3478

Scores

EPSS 0.0489
EPSS Percentile 89.6%

Details

Status published
Products (1)
dayfox_designs/dayfox_blog 4
Published Mar 20, 2007
Tracked Since Feb 18, 2026