CVE-2007-1634

Net Portal Dynamic System < 5.10 - SQL Injection

Title source: rule

Description

Variable extraction vulnerability in grab_globals.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to conduct SQL injection attacks via the _FILES[DB][tmp_name] parameter to print.php, which overwrites the $DB variable with dynamic variable evaluation.

Exploits (1)

exploitdb WORKING POC
phpwebappsphp
https://www.exploit-db.com/exploits/3505

Scores

EPSS 0.0036
EPSS Percentile 57.9%

Classification

Status draft

Affected Products (1)

net_portal_dynamic_system/net_portal_dynamic_system < 5.10

Timeline

Published Mar 23, 2007
Tracked Since Feb 18, 2026