Loading...
Loading...
Direct static code injection vulnerability in admin/save.php in Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier allows remote authenticated administrators to inject PHP code into .html files via the html parameter, as demonstrated by head.html and foot.html, which are included and executed upon a direct request for index.php. NOTE: a separate vulnerability could be leveraged to make this issue exploitable by remote unauthenticated attackers.
April 19, 2007
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2007-2148
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.