Vulnerability record · CVE-2007-3306 · published 21 June 2007
CVE-2007-3306: MiniBill run_billing.php Remote File Inclusion Enables PHP Code Execution
Ultrize · Minibill
MiniBill 1.2.5 contains a remote file inclusion flaw in crontab/run_billing.php, where the config[include_dir] parameter is used to include a remote file without validation. An attacker can point that parameter at a malicious URL and cause the server to execute arbitrary PHP code. This is a distinct vector from CVE-2006-4489.
Description
PHP remote file inclusion vulnerability in crontab/run_billing.php in MiniBill 1.2.5 allows remote attackers to execute arbitrary PHP code via a URL in the config[include_dir] parameter, a different vector than CVE-2006-4489.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityThe flaw allows unauthenticated remote code execution, public exploit code exists, and EPSS is very high, though the product is old and not in KEV.
What it is
MiniBill 1.2.5 contains a remote file inclusion flaw in crontab/run_billing.php, where the config[include_dir] parameter is used to include a remote file without validation. An attacker can point that parameter at a malicious URL and cause the server to execute arbitrary PHP code. This is a distinct vector from CVE-2006-4489.
Impact
Successful exploitation gives the attacker arbitrary PHP code execution in the context of the web server, which can lead to full compromise of the application and its data. The CVSS 2.0 vector indicates partial confidentiality, integrity and availability impact.
Attack surface
The flaw is reachable over the network through crontab/run_billing.php with the config[include_dir] parameter, and the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication is required. No user interaction is described in the record.
Exploitation
The record is not listed in CISA KEV and no ransomware groups are documented as using it, but EPSS is high at 0.64362 (99.196th percentile) and an Exploit-DB entry (4079) exists, indicating public exploit code is available.
What to do
- Upgrade MiniBill to a version later than 1.2.5 if one is available, or apply the vendor fix for the config[include_dir] parameter.
- Disable or remove crontab/run_billing.php if it is not required, and restrict access to it by IP or authentication.
- Set allow_url_include=Off and allow_url_fopen=Off in PHP configuration to block remote file inclusion.
- Validate and whitelist the config[include_dir] value so it cannot contain a URL or path outside the intended directory.
- Run the web application with least privilege and isolate it from sensitive internal systems.
Detection
- Monitor web server and PHP logs for requests to crontab/run_billing.php with config[include_dir] containing http://, https://, ftp:// or other URL schemes.
- Alert on outbound HTTP requests from the web server to unexpected external hosts following access to run_billing.php.
- Search for unexpected PHP files or web shells written to the MiniBill installation directory or web root.
- Review PHP error logs for include or fopen warnings referencing remote URLs in the config[include_dir] parameter.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-3306 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-3306), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.