peter bassill · operator
$ cve CVE-2007-4338 JSON

CVE-2007-4338 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 8.9% (pctl 95)

Patch early

A public exploit exists.

Description

index.php in Ryan Haudenschilt Family Connections (FCMS) before 0.9 allows remote attackers to access an arbitrary account by placing the account's name in the value of an fcms_login_id cookie. NOTE: this can be leveraged for code execution via a POST with PHP code in the content parameter.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS8.93% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2007-08-14
Last modified2026-06-16

Affected (1)

VendorProduct
haudenschiltfamily connections cms

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD