CVE-2007-4921
Ajax File Browser - Code Injection
Title source: ruleDescription
PHP remote file inclusion vulnerability in _includes/settings.inc.php in Ajax File Browser 3 Beta allows remote attackers to execute arbitrary PHP code via a URL in the approot parameter.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by arfis project · textwebappsphp
https://www.exploit-db.com/exploits/4405
References (5)
Scores
EPSS
0.8430
EPSS Percentile
99.3%
Details
CWE
CWE-94
Status
published
Products (1)
ajax/file_browser
3_beta
Published
Sep 17, 2007
Tracked Since
Feb 18, 2026