CVE-2007-0300

TLM CMS <1.1 - RCE

Title source: llm

Description

PHP remote file inclusion vulnerability in i-accueil.php in TLM CMS 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by GoLd_M · textwebappsphp
https://www.exploit-db.com/exploits/3118

Scores

EPSS 0.1379
EPSS Percentile 94.1%

Classification

Status draft

Affected Products (1)

tlm_cms/tlm_cms < 1.1

Timeline

Published Jan 18, 2007
Tracked Since Feb 18, 2026