CVE-2007-5914
JBC Explorer <7.20 RC1 - Code Injection
Title source: llmDescription
Direct static code injection vulnerability in dirsys/modules/config/post.php in JBC Explorer 7.20 RC1 and earlier allows remote authenticated administrators to inject arbitrary PHP code via the DEBUG parameter, which can be executed by accessing config.inc.php. NOTE: this can be exploited by unauthenticated remote attackers by leveraging CVE-2007-5913.
Exploits (1)
References (6)
Scores
EPSS
0.0513
EPSS Percentile
89.7%
Classification
CWE
CWE-94
Status
draft
Affected Products (1)
jean_charles/jbc_explorer
< 7.20_rc1
Timeline
Published
Nov 10, 2007
Tracked Since
Feb 18, 2026