peter bassill · operator
$ cve CVE-2007-1620 JSON

CVE-2007-1620 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 11% (pctl 96)

Patch early

A public exploit exists.

Description

Multiple PHP remote file inclusion vulnerabilities in PHP DB Designer 1.02 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) _SESSION[SITE_PATH] parameter to (a) wind/help.php or (b) wind/about.php, or the (2) _SESSION[DRIVER] parameter to (c) db/session.php.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS11.02% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2007-03-23
Last modified2026-06-16

Affected (1)

VendorProduct
php db designerphp db designer

Public exploits

SourceTitleDate
exploit-dbPHP DB Designer 1.02 - Remote File Inclusion2007-03-16

References

→ the Explorer  ·  watch your stack  ·  NVD