← Back to browse · API

CVE-2007-2422

Severity
CRITICAL
CVSS
9.8
EPSS
0.0243
Risk score
40.05
CISA KEV
No
PoC
No
Published
2007-05-02
Modified
2025-01-17
First seen
2026-08-07
Aliases
EUVD-2007-2417, GHSA-4VJ4-4373-QJ2M
Products
n/a:n/a n/a
Sources
euvd EUVD-2007-2417

Description

Multiple PHP remote file inclusion vulnerabilities in Modules Builder (modbuild) 4.1 for Comdev One Admin allow remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter to (1) config-bak.php or (2) config.php. NOTE: CVE disputes this vulnerability because the unmodified scripts set the applicable variable to the empty string; reasonable modified copies would use a fixed pathname string

References