CVE-2007-4338

Ryan Haudenschilt Family Connections <0.9 - RCE

Title source: llm

Description

index.php in Ryan Haudenschilt Family Connections (FCMS) before 0.9 allows remote attackers to access an arbitrary account by placing the account's name in the value of an fcms_login_id cookie. NOTE: this can be leveraged for code execution via a POST with PHP code in the content parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by ilker Kandemir · phpwebappsphp
https://www.exploit-db.com/exploits/30488

Scores

EPSS 0.3280
EPSS Percentile 96.9%

Details

CWE
CWE-264
Status published
Products (5)
haudenschilt/family_connections_cms 0.1.1
haudenschilt/family_connections_cms 0.1.2
haudenschilt/family_connections_cms 0.5
haudenschilt/family_connections_cms 0.6
haudenschilt/family_connections_cms < 0.8
Published Aug 14, 2007
Tracked Since Feb 18, 2026