Filtered by vendor Php-charts
                         Subscriptions
                    
                    
                
                        Filtered by product Php-charts
                         Subscriptions
                    
                    
                
                    Total
                    1 CVE
                
            | CVE | Vendors | Products | Updated | CVSS v3.1 | 
|---|---|---|---|---|
| CVE-2013-10070 | 1 Php-charts | 1 Php-charts | 2025-08-07 | N/A | 
| PHP-Charts v1.0 contains a PHP code execution vulnerability in wizard/url.php, where user-supplied GET parameter names are passed directly to eval() without sanitization. A remote attacker can exploit this flaw by crafting a request that injects arbitrary PHP code, resulting in command execution under the web server's context. The vulnerability allows unauthenticated attackers to execute system-level commands via base64-encoded payloads embedded in parameter names, leading to full compromise of the host system. | ||||
                            
                                
                                
                                    Page 1 of 1.