CVE detail
CVE-2007-2664 — CVE-2007-2664
Published 2007-05-14 · Modified 2026-06-16 · Vendor tomasz_rekawek · Product yet_another_asterisk_panel · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0280
EPSS probability
exploitation probability, 30d
85.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
PHP remote file inclusion vulnerability in includes/common.php in Yaap 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter, possibly related to the __autoload function.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References