CVE-2007-1152

Pyrophobia 2.1.3.1 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2007-1152. PoCs published by Osirys, laurent gaffie.

AI-analyzed exploit summary This exploit leverages a Local File Inclusion (LFI) vulnerability in Pyrophobia 2.1.3.1 via Apache log injection to achieve Remote Command Execution (RCE). It injects malicious PHP code into the Apache access log and then includes the log file through the LFI vulnerability.

Description

Multiple directory traversal vulnerabilities in Pyrophobia 2.1.3.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) act or (2) pid parameter to the top-level URI (index.php), or the (3) action parameter to admin/index.php. NOTE: some of these details are obtained from third party information.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Osirys · perlwebappsphp
https://www.exploit-db.com/exploits/8095

This exploit leverages a Local File Inclusion (LFI) vulnerability in Pyrophobia 2.1.3.1 via Apache log injection to achieve Remote Command Execution (RCE). It injects malicious PHP code into the Apache access log and then includes the log file through the LFI vulnerability.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Pyrophobia 2.1.3.1
No auth needed
Prerequisites: Target must be running Pyrophobia 2.1.3.1 · Apache access logs must be writable and accessible via LFI
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by laurent gaffie · textwebappsphp
https://www.exploit-db.com/exploits/29632

The provided text describes multiple input-validation vulnerabilities in Pyrophobia, including local file inclusion (LFI) and cross-site scripting (XSS). It includes example URLs demonstrating LFI attacks but does not contain executable exploit code.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Theoretical
Target: Pyrophobia (version not specified)
No auth needed
Prerequisites: Access to the vulnerable Pyrophobia web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37398
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/33861
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/8095
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/22667

Scores

EPSS 0.0273
EPSS Percentile 84.1%

Details

CWE
CWE-22
Status published
Products (1)
pyrophobia/pyrophobia 2.1.3.1
Published Mar 02, 2007
Tracked Since Feb 18, 2026