CVE-2007-4101 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 2.9% (pctl 87)
Patch early
A public exploit exists.
Description
Multiple PHP remote file inclusion vulnerabilities in Madoa Poll 1.1 allow remote attackers to execute arbitrary PHP code via the Madoa parameter to (1) index.php, (2) vote.php, and (3) admin.php.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 2.91% — more likely to be exploited than 87% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-07-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| global centre | aplomb poll |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Global Centre Aplomb Poll 1.1 - 'index.php?Madoa' Remote File Inclusion | 2007-07-30 |
| exploit-db | Global Centre Aplomb Poll 1.1 - 'vote.php?Madoa' Remote File Inclusion | 2007-07-30 |
| exploit-db | Global Centre Aplomb Poll 1.1 - 'admin.php?Madoa' Remote File Inclusion | 2007-07-30 |
References
- http://osvdb.org/37262
- http://osvdb.org/37263
- http://osvdb.org/37264
- http://securityreason.com/securityalert/2937
- http://www.attrition.org/pipermail/vim/2007-July/001739.html
- http://www.securityfocus.com/archive/1/475096/100/0/threaded
- http://www.securityfocus.com/bid/25138
- http://osvdb.org/37262
- http://osvdb.org/37263
- http://osvdb.org/37264
- http://securityreason.com/securityalert/2937
- http://www.attrition.org/pipermail/vim/2007-July/001739.html
- http://www.securityfocus.com/archive/1/475096/100/0/threaded
- http://www.securityfocus.com/bid/25138
→ the Explorer · watch your stack · NVD