CVE-2007-4290
9.8 · CRITICALOverview
CVE-2007-4290 is a critical-severity vulnerability affecting stadtaus guestbook_script. It was published on August 9, 2007 and has a CVSS 3.1 base score of 9.8 (CRITICAL).
This vulnerability has a CVSS 3.1 base score of 9.8, rated CRITICAL. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.
Technical Description
Multiple PHP remote file inclusion vulnerabilities in Guestbook Script 1.9 allow remote attackers to execute arbitrary PHP code via a URL in the script_root parameter to (1) delete.php, (2) edit.php, or (3) inc/common.inc.php; or (4) database.php, (5) entries.php, (6) index.php, (7) logout.php, or (8) settings.php in admin/. NOTE: a third party disputes this vulnerability, noting that these scripts defend against direct requests
Remediation
Check the references section for vendor advisories and patches from stadtaus. Update guestbook_script to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.
Affected Products
| Vendor | Product | Versions | Status |
|---|
References
Frequently Asked Questions
What is CVE-2007-4290?
CVE-2007-4290 is a critical-severity vulnerability affecting stadtaus guestbook_script. It was published on August 9, 2007 and has a CVSS 3.1 base score of 9.8 (CRITICAL).
How severe is CVE-2007-4290?
This vulnerability has a CVSS 3.1 base score of 9.8, rated CRITICAL. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.
How do I fix or remediate CVE-2007-4290?
Check the references section for vendor advisories and patches from stadtaus. Update guestbook_script to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.
How can CyberStrike help with CVE-2007-4290?
CyberStrike's AI-powered security agents can automatically detect CVE-2007-4290 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.
How CyberStrike Helps
AI agents map your attack surface to find vulnerabilities like this one.
Automated penetration testing that runs continuously, not just quarterly.
AI-driven PR review catches vulnerable dependencies before they ship.
Browser-based exploitation validates findings with real proof-of-concept.
Related CRITICAL CVEs from 2007
View all →profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrar
PHP remote file inclusion vulnerability in centipaid_class.php in CentiPaid 1.4.3 allows remote atta
Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote at
PHP remote file inclusion vulnerability in libs/Smarty.class.php in Smarty 2.6.9 allows remote attac
Integer overflow in the 16 bit variable reference counter in PHP 4 allows context-dependent attacker
Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with
Unspecified vulnerability in administration.php in xodagallery allows remote attackers to execute ar
Multiple PHP remote file inclusion vulnerabilities in Modules Builder (modbuild) 4.1 for Comdev One
Multiple SQL injection vulnerabilities in admin.php in phpHoo3 allow remote attackers to execute arb
Multiple PHP remote file inclusion vulnerabilities in myBloggie 2.1.5 allow remote attackers to exec
Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote atta
Argument injection vulnerability involving Mozilla, when certain URIs are registered, allows remote