CVE-2007-1017

VirtualSystem VS-News-System <1.2.1 - RCE

Title source: llm

Description

PHP remote file inclusion vulnerability in show_news_inc.php in VirtualSystem VS-News-System 1.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the newsordner parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by ajann · htmlwebappsphp
https://www.exploit-db.com/exploits/3322

Scores

EPSS 0.1320
EPSS Percentile 94.2%

Details

Status published
Products (1)
virtualsystem/vs-news-system < 1.2.1
Published Feb 21, 2007
Tracked Since Feb 18, 2026