Loading...
Loading...
Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's username, which can be used to (1) obtain sensitive information, including the administrator password, via settings.php or (2) upload and execute arbitrary PHP code via an update_doc action in edit.php.
June 1, 2007
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2007-2985
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.