Loading...
Loading...
cpie.php in XCMS 1.83 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to conduct direct static code injection attacks and execute arbitrary code via the testo_0 parameter in a cpie admin action to index.php, which writes to dati/generali/footer.dtb (aka the XCMS footer).
January 4, 2008
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2007-6652
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.