← Back to CVE List
Vulnerability Intelligence Report

CVE-2007-2736

PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config_atkroot parameter.

No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:4.31%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
apple a_ux all
apple mac_os_x all
hp hp-ux all
hp tru64 all
ibm os2 all
linux linux_kernel all
microsoft windows_2000 all
microsoft windows_2003_server all
microsoft windows_95 all
microsoft windows_98 all
microsoft windows_98se all
microsoft windows_me all
microsoft windows_nt 4.0
microsoft windows_xp all
santa_cruz_operation sco_unix all
sun solaris all
windriver bsdos all
achievo achievo 1.1.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
4.309%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2007-05-17T00:00:00
Published2007-05-17T19:00:00
Patch Date2007-05-15
Last Updated2024-08-07T13:49:57

LINK COPIED TO CLIPBOARD