peter bassill · operator
$ cve CVE-2007-4101 JSON

CVE-2007-4101 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 2.9% (pctl 87)

Patch early

A public exploit exists.

Description

Multiple PHP remote file inclusion vulnerabilities in Madoa Poll 1.1 allow remote attackers to execute arbitrary PHP code via the Madoa parameter to (1) index.php, (2) vote.php, and (3) admin.php.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS2.91% — more likely to be exploited than 87% of all CVEs
On CISA KEVno
Public exploityes
Published2007-07-31
Last modified2026-06-16

Affected (1)

VendorProduct
global centreaplomb poll

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD