CVE-2007-5308
Php Homepage M - SQL Injection
Title source: ruleDescription
SQL injection vulnerability in galerie.php in PHP Homepage M (phpHPm) 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by [PHCN] Mahjong · phpwebappsphp
https://www.exploit-db.com/exploits/4501
References (6)
Scores
EPSS
0.0086
EPSS Percentile
75.0%
Details
CWE
CWE-89
Status
published
Products (1)
php_homepage_m/php_homepage_m
1.0
Published
Oct 09, 2007
Tracked Since
Feb 18, 2026