Loading...
Loading...
Multiple static code injection vulnerabilities in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allow (1) remote authenticated users to inject arbitrary PHP code into files by placing PHP sequences into the account's "display name" setting and then invoking boards/boards_rss.php, and might allow (2) remote attackers to inject arbitrary PHP code into files via the HTTP Host header in a request to boards/boards_rss.php.
May 18, 2009
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2009-1677
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.