peter bassill · operator
$ cve CVE-2007-2736 JSON

CVE-2007-2736 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 4.1% (pctl 90)

Patch early

A public exploit exists.

Description

PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config_atkroot parameter.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS4.09% — more likely to be exploited than 90% of all CVEs
On CISA KEVno
Public exploityes
Published2007-05-17
Last modified2026-06-16

Affected (18)

VendorProduct
achievoachievo
applea ux
applemac os x
hphp-ux
hptru64
ibmos2
linuxlinux kernel
microsoftwindows 2000
microsoftwindows 2003 server
microsoftwindows 95
microsoftwindows 98
microsoftwindows 98se
microsoftwindows me
microsoftwindows nt
microsoftwindows xp
santa cruz operationsco unix
sunsolaris
windriverbsdos

Public exploits

SourceTitleDate
exploit-dbAchievo 1.1.0 - 'config_atkroot' Remote File Inclusion2007-05-15

References

→ the Explorer  ·  watch your stack  ·  NVD