CVE-2007-6105

TalkBack 2.2.7 - RCE

Title source: llm

Description

Multiple PHP remote file inclusion vulnerabilities in TalkBack 2.2.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) language_file parameter to (a) comments-display-tpl.php and (b) addons/separate-comments-mod/my-comments-display-tpl.php and the (2) config[comments_form_tpl] parameter to comments-display-tpl.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by NoGe · textwebappsphp
https://www.exploit-db.com/exploits/4640

Scores

EPSS 0.1368
EPSS Percentile 94.1%

Classification

CWE
CWE-94
Status draft

Affected Products (1)

talkback/talkback

Timeline

Published Nov 23, 2007
Tracked Since Feb 18, 2026