Vulnerabilities > CVE-2007-0504 - Remote Security vulnerability in Vote Pro
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Eval injection vulnerability in poll_frame.php in Vote! Pro 4.0, and possibly other scripts, allows remote attackers to execute arbitrary code via the poll_id parameter, which is supplied to an eval function call, a different vulnerability type than CVE-2005-4632.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Vote-Pro 4.0 (poll_frame.php poll_id) Remote Code Execution Exploit. CVE-2007-0504,CVE-2007-0535. Webapps exploit for php platform |
file | exploits/php/webapps/3180.pl |
id | EDB-ID:3180 |
last seen | 2016-01-31 |
modified | 2007-01-23 |
platform | php |
port | |
published | 2007-01-23 |
reporter | r0ut3r |
source | https://www.exploit-db.com/download/3180/ |
title | Vote-Pro 4.0 poll_frame.php poll_id Remote Code Execution Exploit |
type | webapps |