CVE-2007-5308

Php Homepage M - SQL Injection

Title source: rule

Description

SQL injection vulnerability in galerie.php in PHP Homepage M (phpHPm) 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action.

Exploits (1)

exploitdb WORKING POC VERIFIED
by [PHCN] Mahjong · phpwebappsphp
https://www.exploit-db.com/exploits/4501

Scores

EPSS 0.0086
EPSS Percentile 75.0%

Details

CWE
CWE-89
Status published
Products (1)
php_homepage_m/php_homepage_m 1.0
Published Oct 09, 2007
Tracked Since Feb 18, 2026