CyberSec.Space Logo
Back to CVE Browser

CVE-2007-5035

HIGH
7.5
CVSS Severity Score
EPSS Score0.0130%
EPSS Percentile2.41th
PublishedSep 24, 2007
Last ModifiedApr 23, 2026

Vulnerability Description

PHP remote file inclusion vulnerability in html/modules/extranet_profile/main.php in openEngine 1.9 beta1 allows remote attackers to execute arbitrary PHP code via a URL in the this_module_path parameter. NOTE: this issue is disputed by CVE because PHP encounters a fatal function-call error on a direct request for the file, before reaching the include statement

Affected Platforms (CPE)

πŸ“¦
Openengine

Openengine

= 1.9_beta1
πŸ“¦
Openengine

Openengine

= 1.9_beta2
πŸ“¦
Openengine

Openengine

= 1.9_beta3

References & Advisories

Related Vulnerabilities

CVE-2007-5035 Detail & Impact Analysis | CVSS 7.5 (HIGH) | Cyber-Sec.Space | Cyber-Sec.Space