← Vulnerability feed

Vulnerability record · CVE-2007-4636 · published 31 August 2007

CVE-2007-4636: phpBG rootdir parameter remote file inclusion allows PHP code execution

Phpbg · Phpbg

phpBG 0.9.1 fails to validate the rootdir parameter in five scripts, including intern/admin/other/backup.php and intern/clan/member_add.php, allowing an attacker to supply a remote URL that is included and executed as PHP. Because the included code runs in the web server's context, this is a direct path to full compromise of the application host.

7.5 CVSS 2.0 High EPSS 71% · top 0.6% CWE-20 · Improper input validation
7.5CVSS 2.0 base score
71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

Multiple PHP remote file inclusion vulnerabilities in phpBG 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter to (1) intern/admin/other/backup.php, (2) intern/admin/, (3) intern/clan/member_add.php, (4) intern/config/key_2.php, or (5) intern/config/forum.php.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityUnauthenticated remote code execution with public exploit code and very high EPSS probability, though the product is old and likely limited in deployment.

What it is

phpBG 0.9.1 fails to validate the rootdir parameter in five scripts, including intern/admin/other/backup.php and intern/clan/member_add.php, allowing an attacker to supply a remote URL that is included and executed as PHP. Because the included code runs in the web server's context, this is a direct path to full compromise of the application host.

Impact

An unauthenticated attacker can execute arbitrary PHP code on the server, leading to data theft, web shell placement, and potential full host takeover depending on the web server's privileges.

Attack surface

Reachable over the network via HTTP requests to the listed phpBG scripts with a crafted rootdir parameter; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is 0.71058 (99.374th percentile) and a public Exploit-DB entry (4340) exists, indicating exploit code is publicly available and exploitation is likely.

What to do

  • Upgrade phpBG to a version that validates the rootdir parameter, or remove the product if no fixed release exists.
  • Block remote file inclusion by disabling allow_url_include and allow_url_fopen in php.ini where feasible.
  • Restrict outbound HTTP from the web server and apply egress filtering to prevent retrieval of attacker-hosted payloads.
  • Deploy a WAF rule that rejects requests containing URL schemes (http://, https://, ftp://) in the rootdir parameter.
  • Remove or restrict access to the affected intern/admin and intern/config scripts if they are not required.

Detection

  • Search web server logs for requests to the listed phpBG scripts with rootdir values containing http://, https://, or ftp://.
  • Monitor for unexpected PHP files created in web-accessible directories or outbound HTTP connections from the web server process.
  • Alert on POST or GET parameters named rootdir in requests to phpBG paths, especially from external IPs.
  • Review PHP error logs for include or fopen warnings referencing remote URLs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-4636 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.5CVE-2026-88771Citrix NetScaler Improper Input Validation VulnerabilityImproper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-…KEV9.5CVE-2026-93952Arista velocloud orchestrator improper input validation vulnerabilityVeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…KEVEPSS 0.90%8.8CVE-2019-1068Microsoft SQL Server improper input validation remote code executionMicrosoft SQL Server mishandles processing of internal functions, allowing an authenticated remote attacker to execute code on the database server. T…KEVEPSS 58%analysed5.9CVE-2025-68686FortiOS symbolic link patch bypass exposes sensitive informationFortiOS contains an information exposure flaw (CWE-200) that lets a remote unauthenticated attacker bypass the patch for the symbolic link persistenc…KEVEPSS 30%analysed9.3CVE-2026-12569PTC Windchill PDMlink and FlexPLM deserialization RCEPTC Windchill PDMlink and FlexPLM contain a deserialization of untrusted data flaw (also classified as improper input validation) that allows remote …KEVEPSS 46%analysed10.0CVE-2026-34910Ubiquiti UniFi OS input validation flaw allows command injectionUniFi OS devices contain an improper input validation vulnerability (CWE-20) that lets a network-reachable attacker inject and execute commands. It a…KEVEPSS 46%analysed7.2CVE-2026-6973Ivanti EPMM improper input validation enables remote code executionIvanti Endpoint Manager Mobile (EPMM) before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 contains an improper input validation flaw (CWE-20) that lets …KEVEPSS 2.5%analysed7.5CVE-2026-20133Cisco Catalyst SD-WAN Manager insufficient file system restrictions expose dataCisco Catalyst SD-WAN Software has insufficient file system restrictions that let an attacker read sensitive files on the underlying operating system…KEVEPSS 32%analysed

Source: NIST National Vulnerability Database (record CVE-2007-4636), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.