← Vulnerability feed

Vulnerability record · CVE-2007-3306 · published 21 June 2007

CVE-2007-3306: MiniBill run_billing.php Remote File Inclusion Enables PHP Code Execution

Ultrize · Minibill

MiniBill 1.2.5 contains a remote file inclusion flaw in crontab/run_billing.php, where the config[include_dir] parameter is used to include a remote file without validation. An attacker can point that parameter at a malicious URL and cause the server to execute arbitrary PHP code. This is a distinct vector from CVE-2006-4489.

7.5 CVSS 2.0 High EPSS 64% · top 0.8%
7.5CVSS 2.0 base score
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

PHP remote file inclusion vulnerability in crontab/run_billing.php in MiniBill 1.2.5 allows remote attackers to execute arbitrary PHP code via a URL in the config[include_dir] parameter, a different vector than CVE-2006-4489.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe flaw allows unauthenticated remote code execution, public exploit code exists, and EPSS is very high, though the product is old and not in KEV.

What it is

MiniBill 1.2.5 contains a remote file inclusion flaw in crontab/run_billing.php, where the config[include_dir] parameter is used to include a remote file without validation. An attacker can point that parameter at a malicious URL and cause the server to execute arbitrary PHP code. This is a distinct vector from CVE-2006-4489.

Impact

Successful exploitation gives the attacker arbitrary PHP code execution in the context of the web server, which can lead to full compromise of the application and its data. The CVSS 2.0 vector indicates partial confidentiality, integrity and availability impact.

Attack surface

The flaw is reachable over the network through crontab/run_billing.php with the config[include_dir] parameter, and the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication is required. No user interaction is described in the record.

Exploitation

The record is not listed in CISA KEV and no ransomware groups are documented as using it, but EPSS is high at 0.64362 (99.196th percentile) and an Exploit-DB entry (4079) exists, indicating public exploit code is available.

What to do

  • Upgrade MiniBill to a version later than 1.2.5 if one is available, or apply the vendor fix for the config[include_dir] parameter.
  • Disable or remove crontab/run_billing.php if it is not required, and restrict access to it by IP or authentication.
  • Set allow_url_include=Off and allow_url_fopen=Off in PHP configuration to block remote file inclusion.
  • Validate and whitelist the config[include_dir] value so it cannot contain a URL or path outside the intended directory.
  • Run the web application with least privilege and isolate it from sensitive internal systems.

Detection

  • Monitor web server and PHP logs for requests to crontab/run_billing.php with config[include_dir] containing http://, https://, ftp:// or other URL schemes.
  • Alert on outbound HTTP requests from the web server to unexpected external hosts following access to run_billing.php.
  • Search for unexpected PHP files or web shells written to the MiniBill installation directory or web root.
  • Review PHP error logs for include or fopen warnings referencing remote URLs in the config[include_dir] parameter.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-3306 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2007-3306), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.