AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2007-4338

HIGH · CVSS 10 EPSS 8.92% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2007-08-14 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2007-4338
Severity
HIGH
CVSS
10
EPSS
8.92%

Original NVD Description

index.php in Ryan Haudenschilt Family Connections (FCMS) before 0.9 allows remote attackers to access an arbitrary account by placing the account's name in the value of an fcms_login_id cookie. NOTE: this can be leveraged for code execution via a POST with PHP code in the content parameter.