VulnerabilityModified
CVE-2007-4101
Multiple PHP remote file inclusion vulnerabilities in Madoa Poll 1.1 allow remote attackers to execute arbitrary PHP code via the Madoa parameter to (1) index.php, (2) vote.php, and (3) admin.php.
MEDIUM 6.8EPSS 2.91%
Does this matter?
Lower severity and a low EPSS score (2.91%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple PHP remote file inclusion vulnerabilities in Madoa Poll 1.1 allow remote attackers to execute arbitrary PHP code via the Madoa parameter to (1) index.php, (2) vote.php, and (3) admin.php.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 2.91% probability · 86th percentile
- CISA KEV
- Not listed
- Affected
- global centre/aplomb poll
- Source
- cve@mitre.org
References
- http://osvdb.org/37262
- http://osvdb.org/37263
- http://osvdb.org/37264
- http://securityreason.com/securityalert/2937
- http://www.attrition.org/pipermail/vim/2007-July/001739.html
- http://www.securityfocus.com/archive/1/475096/100/0/threaded
- http://www.securityfocus.com/bid/25138Exploit
- http://osvdb.org/37262
- http://osvdb.org/37263
- http://osvdb.org/37264
- http://securityreason.com/securityalert/2937
- http://www.attrition.org/pipermail/vim/2007-July/001739.html
- http://www.securityfocus.com/archive/1/475096/100/0/threaded
- http://www.securityfocus.com/bid/25138Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.