AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2007-2422

CRITICAL · CVSS 9.8 EPSS 2.43%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2007-05-02 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. It may be remotely exploitable.

CVE
CVE-2007-2422
Severity
CRITICAL
CVSS
9.8
EPSS
2.43%

Original NVD Description

Multiple PHP remote file inclusion vulnerabilities in Modules Builder (modbuild) 4.1 for Comdev One Admin allow remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter to (1) config-bak.php or (2) config.php. NOTE: CVE disputes this vulnerability because the unmodified scripts set the applicable variable to the empty string; reasonable modified copies would use a fixed pathname string