📦

hot_or_not_clone

Vendor: hotscripts

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 0 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 2.86% Exploit Prob.
Latest CVE CVE-2007-6603 Dec 31

Security Vulnerability Index

Page 1 / 1
5.0 CVSS
CVE-2007-6603
Exploit Found

Hot or Not Clone has insufficient access control for producing and reading database backups, which allows remote attackers to obtain the administrator username and password via a direct request to control/backup/backup.php, which generates a backup/dump/backup.sql file that can be downloaded via a direct request to control/downloadfile.php.

EPSS: 2.86%