Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2007-4338

index.php in Ryan Haudenschilt Family Connections (FCMS) before 0.9 allows remote attackers to access an arbitrary account by placing the account's name in the value of an fcms_login_id cookie. NOTE: this can be leveraged for code execution via a POST with PHP code in the content parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.374
EPSS Ranking 97.0%
CVSS Severity
CVSS v2 Score 10.0
References
Products affected by CVE-2007-4338


Contact Us

Shodan ® - All rights reserved