Direct static code injection vulnerability in phpBook 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via the e-mail field (mail variable) in a new message, which is written to a PHP file.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.078
                        
                    
                    
                        
                            EPSS Ranking 91.6%