CVE-2007-1839

CodeBB < 1.1_beta_3 - Remote File Inclusion via phpbb_root_path Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-1839. PoCs published by Alkomandoz Hacker.

AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in CodeBB 1.1b3 by manipulating the `phpbb_root_path` parameter to include arbitrary files, potentially leading to remote code execution.

Description

Multiple PHP remote file inclusion vulnerabilities in CodeBB 1.1b3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) pass_code.php or (2) lang_select.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Alkomandoz Hacker · textwebappsphp
https://www.exploit-db.com/exploits/3599

This exploit demonstrates a remote file inclusion vulnerability in CodeBB 1.1b3 by manipulating the `phpbb_root_path` parameter to include arbitrary files, potentially leading to remote code execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: CodeBB 1.1b3
No auth needed
Prerequisites: Target must have CodeBB 1.1b3 installed · Remote file inclusion must be enabled on the server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/33293
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/23185
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/35423
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/3599
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1148
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/35422

Scores

EPSS 0.0328
EPSS Percentile 86.8%

Details

Status published
Products (1)
codebb/codebb < 1.1_beta_3
Published Apr 03, 2007
Tracked Since Feb 18, 2026