Vulnerabilities > CVE-2007-0504 - Remote Security vulnerability in Vote Pro

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
vote-pro
critical
exploit available

Summary

Eval injection vulnerability in poll_frame.php in Vote! Pro 4.0, and possibly other scripts, allows remote attackers to execute arbitrary code via the poll_id parameter, which is supplied to an eval function call, a different vulnerability type than CVE-2005-4632.

Vulnerable Configurations

Part Description Count
Application
Vote_Pro
1

Exploit-Db

descriptionVote-Pro 4.0 (poll_frame.php poll_id) Remote Code Execution Exploit. CVE-2007-0504,CVE-2007-0535. Webapps exploit for php platform
fileexploits/php/webapps/3180.pl
idEDB-ID:3180
last seen2016-01-31
modified2007-01-23
platformphp
port
published2007-01-23
reporterr0ut3r
sourcehttps://www.exploit-db.com/download/3180/
titleVote-Pro 4.0 poll_frame.php poll_id Remote Code Execution Exploit
typewebapps