CVE-2007-4636
phpBG 0.9.1 - RCE
Title source: llmDescription
Multiple PHP remote file inclusion vulnerabilities in phpBG 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter to (1) intern/admin/other/backup.php, (2) intern/admin/, (3) intern/clan/member_add.php, (4) intern/config/key_2.php, or (5) intern/config/forum.php.
Exploits (1)
References (8)
Scores
EPSS
0.8203
EPSS Percentile
99.2%
Details
CWE
CWE-20
Status
published
Products (1)
phpbg/phpbg
0.9.1
Published
Aug 31, 2007
Tracked Since
Feb 18, 2026