CVE-2007-4338
Ryan Haudenschilt Family Connections <0.9 - RCE
Title source: llmDescription
index.php in Ryan Haudenschilt Family Connections (FCMS) before 0.9 allows remote attackers to access an arbitrary account by placing the account's name in the value of an fcms_login_id cookie. NOTE: this can be leveraged for code execution via a POST with PHP code in the content parameter.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by ilker Kandemir · phpwebappsphp
https://www.exploit-db.com/exploits/30488
References (10)
Scores
EPSS
0.3280
EPSS Percentile
96.9%
Details
CWE
CWE-264
Status
published
Products (5)
haudenschilt/family_connections_cms
0.1.1
haudenschilt/family_connections_cms
0.1.2
haudenschilt/family_connections_cms
0.5
haudenschilt/family_connections_cms
0.6
haudenschilt/family_connections_cms
< 0.8
Published
Aug 14, 2007
Tracked Since
Feb 18, 2026