CVE-2007-1635

Net Portal Dynamic System <5.10 - Code Injection

Title source: llm

Description

Static code injection vulnerability in admin/settings.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote authenticated users to inject arbitrary PHP code via the xtop parameter in a "ConfigSave" op to admin.php, which can later be accessed via a "Configure" op to admin.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by DarkFig · phpwebappsphp
https://www.exploit-db.com/exploits/3505

Scores

EPSS 0.0331
EPSS Percentile 87.3%

Details

Status published
Products (1)
net_portal_dynamic_system/net_portal_dynamic_system < 5.10
Published Mar 23, 2007
Tracked Since Feb 18, 2026