Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-1635. PoCs published by DarkFig.
AI-analyzed exploit summary This exploit targets CVE-2007-1635, a vulnerability in Net Portal Dynamic System (NPDS) <= 5.10. It combines SQL injection to extract admin credentials and a code execution flaw to achieve remote command execution.
Description
Static code injection vulnerability in admin/settings.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote authenticated users to inject arbitrary PHP code via the xtop parameter in a "ConfigSave" op to admin.php, which can later be accessed via a "Configure" op to admin.php.
Exploits (1)
This exploit targets CVE-2007-1635, a vulnerability in Net Portal Dynamic System (NPDS) <= 5.10. It combines SQL injection to extract admin credentials and a code execution flaw to achieve remote command execution.