CVE-2007-0489

VisoHotlink 1.01 - RCE

Title source: llm

Description

PHP remote file inclusion vulnerability in includes/functions.visohotlink.php in VisoHotlink 1.01 and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by bd0rk · perlwebappsphp
https://www.exploit-db.com/exploits/3175

Scores

EPSS 0.1254
EPSS Percentile 94.0%

Details

Status published
Products (1)
visohotlink/visohotlink < 1.01
Published Jan 25, 2007
Tracked Since Feb 18, 2026