CVE-2007-2985
Status: ModifiedHigh (10)—💥 Exploit
Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's username, which can be used to (1) obtain sensitive information, including the administrator password, via settings.php or (2) upload and execute arbitrary PHP code via an update_doc action in edit.php.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
- Base score: 10
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 4.17%
- Percentile among all scored CVEs: 91
- Score date: 10/8/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Published on Exploit-DB · Pheap 2.0 - Authentication Bypass / Remote Code Execution (5/29/2007)
Affected technologies (1)
CWEs
- CWE-264
References
- http://osvdb.org/36737
- http://secunia.com/advisories/25460
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34592
- https://www.exploit-db.com/exploits/4006
- http://osvdb.org/36737
- http://secunia.com/advisories/25460
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34592
- https://www.exploit-db.com/exploits/4006
Raw JSON (NVD)
Show
{
"id": "CVE-2007-2985",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-06-01T10:30:00.000",
"references": [
{
"url": "http://osvdb.org/36737",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/25460",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34592",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/4006",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/36737",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/25460",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34592",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/4006",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's username, which can be used to (1) obtain sensitive information, including the administrator password, via settings.php or (2) upload and execute arbitrary PHP code via an update_doc action in edit.php."
},
{
"lang": "es",
"value": "Pheap versión 2.0, permite a atacantes remotos omitir la autenticación estableciendo un valor de cookie de pheap_login al nombre de usuario del administrador, que puede ser usado para (1) obtener información confidencial, incluida la contraseña del administrador, por medio del archivo settings.php o (2) cargar y ejecutar código PHP arbitrario por medio de una acción update_doc en el archivo edit.php."
}
],
"lastModified": "2026-06-16T22:40:50.030",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:pheap:pheap:2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "50AA8836-AE3E-4DE0-8688-0B1C1341E740"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}