CVE-2007-1998 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 8.7% (pctl 95)
Patch early
A public exploit exists.
Description
Direct static code injection vulnerability in HIOX Guest Book (HGB) 4.0 allows remote attackers to inject arbitrary PHP code via the Email field, which results in code execution through a direct request to gb.php.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 8.75% — more likely to be exploited than 95% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-04-12 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| hiox india | guest book |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | HIOX GUEST BOOK (HGB) 4.0 - Remote Code Execution | 2007-04-10 |
References
- http://secunia.com/advisories/24835
- http://www.vupen.com/english/advisories/2007/1333
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33540
- https://www.exploit-db.com/exploits/3697
- http://secunia.com/advisories/24835
- http://www.vupen.com/english/advisories/2007/1333
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33540
- https://www.exploit-db.com/exploits/3697
→ the Explorer · watch your stack · NVD