NVD

Id
55144  
Name
CVE-2007-2985  
Description
Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator"s username, which can be used to (1) obtain sensitive information, including the administrator password, via settings.php or (2) upload and execute arbitrary PHP code via an update_doc action in edit.php.  
Reject
 
CVSS Version
2  
CVSS Score
10  
Severity
High  
CVSS Base Score
10  
CVSS Impact Subscore
10  
CVSS Exploit Subscore
10  
CVSS Vector
(AV:N/AC:L/Au:N/C:C/I:C/A:C)  
Pub Date
2017-01-07  
Published
2007-06-01  
Modified Date
2008-11-15  
Seq
2007-2985  

Actions