CVE-2007-2762
Last modified
CVE-2007-2762 is a vulnerability of currently unknown severity. Multiple PHP remote file inclusion vulnerabilities in Build it Fast (bif3) 0.4.1 allow remote attackers to execute arbitrary PHP code via a URL in (1) the pear_dir parameter to Base/Application.php, or the (2) sys_dir parameter to (a) Footer.php, (b) widget.BifContainer.php, (c) widget.BifRoot.php, (d) widget.BifRoot2.php, (e) widget.BifRoot3.php, or (f) widget.BifWarning.php in Widgets/Base/.. EPSS estimates a 9.65% chance of exploitation in the next 30 days.
Description
Multiple PHP remote file inclusion vulnerabilities in Build it Fast (bif3) 0.4.1 allow remote attackers to execute arbitrary PHP code via a URL in (1) the pear_dir parameter to Base/Application.php, or the (2) sys_dir parameter to (a) Footer.php, (b) widget.BifContainer.php, (c) widget.BifRoot.php, (d) widget.BifRoot2.php, (e) widget.BifRoot3.php, or (f) widget.BifWarning.php in Widgets/Base/.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Build It Fast | Build It Fast | 0.4.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-2762?
How severe is CVE-2007-2762?
How do I fix CVE-2007-2762?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-2756The gdPngReadData function in libgd 2.0.34 allows user-assis…
- CVE-2007-2757Multiple cross-site scripting (XSS) vulnerabilities in Redoa…
- CVE-2007-2758Multiple buffer overflows in WinImage 8.0.8000 allow user-as…
- CVE-2007-2759Multiple SQL injection vulnerabilities in the insert functio…
- CVE-2007-2760The canUpdate function in model/MRole.java in Adempiere befo…
- CVE-2007-2761Stack-based buffer overflow in MagicISO 5.4 build 239 and ea…
- CVE-2007-2763Buffer overflow in the UnlockSupport function in the LockMod…
- CVE-2007-2764The embedded Linux kernel in certain Sun-Brocade SilkWorm sw…
- CVE-2007-2765blockhosts.py in BlockHosts before 2.0.3 does not properly p…
- CVE-2007-2766lib/backup-methods.sh in Backup Manager before 0.7.6 provide…
- CVE-2007-2767Unspecified vulnerability in BES before 3.5.0 in OPeNDAP 4 (…
- CVE-2007-2768OpenSSH, when using OPIE (One-Time Passwords in Everything) …
Are you affected by CVE-2007-2762?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
