1 results (0.005 seconds)

CVSS: 9.8EPSS: 32%CPEs: 5EXPL: 1

04 Jan 2006 — Direct static code injection vulnerability in phpBook 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via the e-mail field (mail variable) in a new message, which is written to a PHP file. • https://www.exploit-db.com/exploits/26999 •