Vulnerability record · CVE-2007-4636 · published 31 August 2007
CVE-2007-4636: phpBG rootdir parameter remote file inclusion allows PHP code execution
Phpbg · Phpbg
phpBG 0.9.1 fails to validate the rootdir parameter in five scripts, including intern/admin/other/backup.php and intern/clan/member_add.php, allowing an attacker to supply a remote URL that is included and executed as PHP. Because the included code runs in the web server's context, this is a direct path to full compromise of the application host.
Description
Multiple PHP remote file inclusion vulnerabilities in phpBG 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter to (1) intern/admin/other/backup.php, (2) intern/admin/, (3) intern/clan/member_add.php, (4) intern/config/key_2.php, or (5) intern/config/forum.php.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote code execution with public exploit code and very high EPSS probability, though the product is old and likely limited in deployment.
What it is
phpBG 0.9.1 fails to validate the rootdir parameter in five scripts, including intern/admin/other/backup.php and intern/clan/member_add.php, allowing an attacker to supply a remote URL that is included and executed as PHP. Because the included code runs in the web server's context, this is a direct path to full compromise of the application host.
Impact
An unauthenticated attacker can execute arbitrary PHP code on the server, leading to data theft, web shell placement, and potential full host takeover depending on the web server's privileges.
Attack surface
Reachable over the network via HTTP requests to the listed phpBG scripts with a crafted rootdir parameter; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.71058 (99.374th percentile) and a public Exploit-DB entry (4340) exists, indicating exploit code is publicly available and exploitation is likely.
What to do
- Upgrade phpBG to a version that validates the rootdir parameter, or remove the product if no fixed release exists.
- Block remote file inclusion by disabling allow_url_include and allow_url_fopen in php.ini where feasible.
- Restrict outbound HTTP from the web server and apply egress filtering to prevent retrieval of attacker-hosted payloads.
- Deploy a WAF rule that rejects requests containing URL schemes (http://, https://, ftp://) in the rootdir parameter.
- Remove or restrict access to the affected intern/admin and intern/config scripts if they are not required.
Detection
- Search web server logs for requests to the listed phpBG scripts with rootdir values containing http://, https://, or ftp://.
- Monitor for unexpected PHP files created in web-accessible directories or outbound HTTP connections from the web server process.
- Alert on POST or GET parameters named rootdir in requests to phpBG paths, especially from external IPs.
- Review PHP error logs for include or fopen warnings referencing remote URLs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-4636 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-4636), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.