Record summary

CVE-2007-2064 has a selected CVSS score of 7.5; EIP currently links 2 catalogued exploits.

Description

Multiple PHP remote file inclusion vulnerabilities in Robert Ladstaetter ActionPoll 1.1.0, and possibly 1.1.1, allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG_POLLDB parameter to actionpoll.php or (2) the CONFIG_DB parameter to db/DataReaderWriter.php, different vectors than CVE-2001-1297.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBActionpoll 1.1.1 - '/db/DataReaderWriter.php?CONFIG_DB' Remote File InclusionExploitDB exploitby Cyber SecurityNot analyzed1 file
ExploitDB

PoC details
ExploitDBActionpoll 1.1 - 'Actionpoll.php' Remote File InclusionExploitDB exploitby SekoMirzaNot analyzed1 file
ExploitDB

PoC details

References

6