Loading vulnerability details…
CVSS v3.1
N/A
EPSS
44.43%
Published
Apr 22, 2007
Modified
Jun 16, 2026
Public PoC / Exploit (2)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Static code injection vulnerability in process.php in AimStats 3.2 allows remote attackers to inject PHP code into config.php via the number parameter in an update action.
Affected Products (1)
References (12)