CVE-2007-4338 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 8.9% (pctl 95)
Patch early
A public exploit exists.
Description
index.php in Ryan Haudenschilt Family Connections (FCMS) before 0.9 allows remote attackers to access an arbitrary account by placing the account's name in the value of an fcms_login_id cookie. NOTE: this can be leveraged for code execution via a POST with PHP code in the content parameter.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 8.93% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-08-14 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| haudenschilt | family connections cms |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Haudenschilt Family Connections 0.8 - 'index.php' Authentication Bypass | 2007-08-11 |
References
- http://osvdb.org/39534
- http://secunia.com/advisories/26421
- http://securityreason.com/securityalert/3009
- http://sourceforge.net/tracker/index.php?func=detail&aid=1778696&group_id=189733&atid=930513
- http://www.attrition.org/pipermail/vim/2007-August/001762.html
- http://www.attrition.org/pipermail/vim/2007-August/001768.html
- http://www.securityfocus.com/archive/1/476142/100/0/threaded
- http://www.securityfocus.com/archive/1/476293/100/0/threaded
- http://www.securityfocus.com/bid/25276
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35966
- http://osvdb.org/39534
- http://secunia.com/advisories/26421
- http://securityreason.com/securityalert/3009
- http://sourceforge.net/tracker/index.php?func=detail&aid=1778696&group_id=189733&atid=930513
- http://www.attrition.org/pipermail/vim/2007-August/001762.html
- http://www.attrition.org/pipermail/vim/2007-August/001768.html
- http://www.securityfocus.com/archive/1/476142/100/0/threaded
- http://www.securityfocus.com/archive/1/476293/100/0/threaded
- http://www.securityfocus.com/bid/25276
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35966
→ the Explorer · watch your stack · NVD