Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2007-3586

Multiple direct static code injection vulnerabilities in MyCMS 0.9.8 and earlier allow remote attackers to inject arbitrary PHP code into (1) a _score.txt file via the score parameter, or (2) a _setby.txt file via a login cookie, which is then included by games.php. NOTE: programs that use games.php might include (a) snakep.php, (b) tetrisp.php, and possibly other site-specific files.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.058
EPSS Ranking 90.5%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2007-3586
  • Mycms » Mycms » Version: Any
    cpe:2.3:a:mycms:mycms:*


Contact Us

Shodan ® - All rights reserved