Vulnerability Details CVE-2007-1073
Static code injection vulnerability in install.php in mcRefer allows remote attackers to execute arbitrary PHP code via the bgcolor parameter, which is inserted into mcrconf.inc.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.01
EPSS Ranking 75.8%
CVSS Severity
CVSS v2 Score 10.0
Products affected by CVE-2007-1073
-
cpe:2.3:a:mcrefer:mcrefer:*