HIGH
Static code injection vulnerability in admin/settings.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote authenticated users to inject arbitrary PHP code via the xtop parameter in a "ConfigSave" op to admin.php, which can later be accessed via a "Configure" op to admin.php
Published Mar 23, 2007
9.0
HIGHCVSS 2.0
EPSS 2.78%
Description
Affected products
Remediation
Metrics
References (4)
Change history (0)
No recorded changes yet.