CVE-2007-2257
Fully Modded phpBB2 - RCE
Title source: llmDescription
PHP remote file inclusion vulnerability in subscp.php in Fully Modded phpBB2 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by HACKERS PAL · phpwebappsphp
https://www.exploit-db.com/exploits/29869
References (5)
Scores
EPSS
0.0273
EPSS Percentile
86.0%
Details
Status
published
Products (1)
fully_modded_phpbb/fully_modded_phpbb2
Published
Apr 25, 2007
Tracked Since
Feb 18, 2026