peter bassill · operator
$ cve CVE-2007-0804 JSON

CVE-2007-0804 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.5% (pctl 85)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in admin/subpages.php in GGCMS 1.1.0 RC1 and earlier allows remote attackers to inject arbitrary PHP code into arbitrary files via ".." sequences in the subpageName parameter, as demonstrated by injecting PHP code into a template file.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.54% — more likely to be exploited than 85% of all CVEs
On CISA KEVno
Public exploityes
Published2007-02-07
Last modified2026-06-16

Affected (1)

VendorProduct
ggcmsggcms

Public exploits

SourceTitleDate
exploit-dbGGCMS 1.1.0 RC1 - Remote Code Execution2007-02-05

References

→ the Explorer  ·  watch your stack  ·  NVD