CVE-2007-1525

Publication date

2007-03-20 20:00:00

Family

mitre

State

PUBLISHED

Description

Direct static code injection vulnerability in postpost.php in Dayfox Blog (dfblog) 4 allows remote attackers to execute arbitrary PHP code via the cat parameter, which can be executed via a request to posts.php.