peter bassill · operator
$ cve CVE-2007-2001 JSON

CVE-2007-2001 EXPLOIT

6.5
MEDIUM · CVSS 2.0 · EPSS 2% (pctl 80)

Patch early

A public exploit exists.

Description

Multiple direct static code injection vulnerabilities in admin/configurer2.php in Crea-Book 1.0 and earlier allow remote authenticated administrators to execute arbitrary PHP code via the "Fond de la page" (background color) field and other unspecified fields, which injects into config.inc.php3.

Scoring

CVSS6.5 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS2.02% — more likely to be exploited than 80% of all CVEs
On CISA KEVno
Public exploityes
Published2007-04-12
Last modified2026-06-16

Affected (1)

VendorProduct
crea-bookcrea-book

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD