peter bassill · operator
$ cve CVE-2007-1721 JSON

CVE-2007-1721 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 13.3% (pctl 96)

Patch early

A public exploit exists.

Description

Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) Richtxt_functions.inc.php, (2) adddocfile.php, (3) auth_check.php, (4) browse_current_category.inc.php, (5) docfile_details.php, (6) main.php, (7) mainarticle.php, (8) maindocfile.php, (9) modify.php, (10) new.php, (11) resource_details.php, or (12) smallsearch.php in lib/; or (13) mwiki/LocalSettings.php.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS13.32% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2007-03-28
Last modified2026-06-16

Affected (1)

VendorProduct
realinkc-arbre

Public exploits

SourceTitleDate
exploit-dbC-Arbre 0.6PR7 - 'ROOT_PATH' Remote File Inclusion2007-03-26

References

→ the Explorer  ·  watch your stack  ·  NVD