Loading vulnerability details…
CVSS v3.1
N/A
EPSS
1.96%
Published
Oct 30, 2007
Modified
Jun 16, 2026
Public PoC / Exploit (2)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Unrestricted file upload vulnerability in the profiles script in ProfileCMS 1.0 allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors involving creation of a profile.
Weaknesses (CWE)
Affected Products (1)
References (8)