← back
CVE-2007-1635

CVE-2007-1635

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 2.8%
from disclosure to weapon0 days
Published on NVDMar 23
1st PoCMar 18
exploitation probability
2.8%top 15% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Static code injection vulnerability in admin/settings.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote authenticated users to inject arbitrary PHP code via the xtop parameter in a "ConfigSave" op to admin.php, which can later be accessed via a "Configure" op to admin.php.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.