← Vulnerability feed

Vulnerability record · CVE-2007-2986 · published 1 June 2007

CVE-2007-2986: AdminBot MX PHP remote file inclusion in live_status.lib.php

NNexen · Adminbot Mx

AdminBot MX 9.0.5 contains a PHP remote file inclusion flaw in lib/live_status.lib.php, where the ROOT parameter is used to include a remote file without validation. An attacker can point ROOT at a hostile URL and cause arbitrary PHP code to execute on the server. The record does not specify the exact vulnerable code path beyond the ROOT parameter.

7.5 CVSS 2.0 High EPSS 64% · top 0.8%
7.5CVSS 2.0 base score
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

PHP remote file inclusion vulnerability in lib/live_status.lib.php in AdminBot MX 9.0.5 allows remote attackers to execute arbitrary PHP code via a URL in the ROOT parameter.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated remote code execution with public exploit code and a very high EPSS score, though no KEV listing and no confirmed fixed version in the record.

What it is

AdminBot MX 9.0.5 contains a PHP remote file inclusion flaw in lib/live_status.lib.php, where the ROOT parameter is used to include a remote file without validation. An attacker can point ROOT at a hostile URL and cause arbitrary PHP code to execute on the server. The record does not specify the exact vulnerable code path beyond the ROOT parameter.

Impact

Successful exploitation gives the attacker remote code execution in the context of the web server, allowing full compromise of the application and any data or host resources it can reach. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as partial.

Attack surface

The flaw is reachable over the network through HTTP requests to lib/live_status.lib.php with a crafted ROOT parameter. The CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

CISA KEV does not list this CVE, but EPSS is 0.64362 (99.196th percentile), indicating a high modeled likelihood of exploitation activity. A public Exploit-DB entry (4005) is referenced, so exploit code is publicly available.

What to do

  • Upgrade AdminBot MX to a version later than 9.0.5 if one exists; the record does not name a fixed version, so confirm with the vendor.
  • If no patch is available, disable or remove lib/live_status.lib.php or block direct HTTP access to it.
  • Set PHP allow_url_include=Off and allow_url_fopen=Off to prevent remote file inclusion.
  • Validate and whitelist the ROOT parameter so it cannot contain a URL or path traversal sequence.
  • Isolate the AdminBot MX host with network controls and restrict outbound traffic to limit post-exploitation movement.

Detection

  • Search web logs for requests to lib/live_status.lib.php with a ROOT parameter containing http://, https://, ftp:// or other URL schemes.
  • Monitor for unexpected outbound HTTP connections from the web server to external hosts shortly after requests to AdminBot MX PHP files.
  • Look for newly written PHP files or web shells in the AdminBot MX web root and other writable directories.
  • Alert on PHP include or require errors referencing remote URLs in application or server error logs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-2986 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2007-2986), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.