CVE-2007-0535 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 3.6% (pctl 89)
Patch early
A public exploit exists.
Description
Multiple eval injection vulnerabilities in Vote! Pro 4.0, and possibly earlier, allow remote attackers to execute arbitrary code via requests to unspecified PHP scripts with the poll_id parameter, which is supplied to eval function calls, a different set of vectors than CVE-2007-0504. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 3.64% — more likely to be exploited than 89% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-01-26 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| vote pro | vote pro |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Vote-Pro 4.0 - 'poll_frame.php?poll_id' Remote Code Execution | 2007-01-23 |
References
→ the Explorer · watch your stack · NVD