CVE-2007-2899

NavBoard 2.6.0 - Code Injection

Title source: llm

Description

Direct static code injection vulnerability in admin_config.php in NavBoard 2.6.0 allows remote attackers to inject arbitrary PHP code into data/config.php via multiple parameters, as demonstrated via the threadperpage parameter in an editconfig action.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Dj7xpl · phpwebappsphp
https://www.exploit-db.com/exploits/3971

Scores

EPSS 0.0578
EPSS Percentile 90.5%

Details

CWE
CWE-94
Status published
Products (1)
navboard/navboard 16
Published May 30, 2007
Tracked Since Feb 18, 2026