AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2007-1635

HIGH · CVSS 9 EPSS 2.78%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2007-03-23 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2007-1635
Severity
HIGH
CVSS
9
EPSS
2.78%

Original NVD Description

Static code injection vulnerability in admin/settings.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote authenticated users to inject arbitrary PHP code via the xtop parameter in a "ConfigSave" op to admin.php, which can later be accessed via a "Configure" op to admin.php.