PHP remote file inclusion vulnerability in include.php in Comdev CSV Importer 3.1 and possibly 4.1, as used in (1) Comdev Contact Form 3.1, (2) Comdev Customer Helpdesk 3.1, (3) Comdev Events Calendar 3.1, (4) Comdev FAQ Support 3.1, (5) Comdev Guestbook 3.1, (6) Comdev Links Directory 3.1, (7) Comdev News Publisher 3.1, (8) Comdev Newsletter 3.1, (9) Comdev Photo Gallery 3.1, (10) Comdev Vote Caster 3.1, (11) Comdev Web Blogger 3.1, and (12) Comdev eCommerce 3.1, allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter
Published Oct 2, 2006
7.5
HIGHCVSS 2.0
EPSS 6.14%
Description
PHP remote file inclusion vulnerability in include.php in Comdev CSV Importer 3.1 and possibly 4.1, as used in (1) Comdev Contact Form 3.1, (2) Comdev Customer Helpdesk 3.1, (3) Comdev Events Calendar 3.1, (4) Comdev FAQ Support 3.1, (5) Comdev Guestbook 3.1, (6) Comdev Links Directory 3.1, (7) Comdev News Publisher 3.1, (8) Comdev Newsletter 3.1, (9) Comdev Photo Gallery 3.1, (10) Comdev Vote Caster 3.1, (11) Comdev Web Blogger 3.1, and (12) Comdev eCommerce 3.1, allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter. NOTE: it has been reported that 4.1 versions might also be affected.
Affected products
No data.
- 3.1
- 4.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
2022-2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (19 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 6.14% (0.06140) | 93.25th | v5 (v2026.06.15) |
| Aug 30, 2026 | 6.14% (0.06140) | 92.94th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.65% (0.03651) | 88.12th | v5 (v2026.06.15) |
| Oct 26, 2025 | 5.85% (0.05850) | 90.12th | v4 (v2025.03.14) |
| Aug 6, 2025 | 3.62% (0.03618) | 87.37th | v4 (v2025.03.14) |
| May 21, 2025 | 4.82% (0.04820) | 88.95th | v4 (v2025.03.14) |
| Mar 30, 2025 | 2.82% (0.02817) | 84.89th | v4 (v2025.03.14) |
| Mar 29, 2025 | 5.18% (0.05184) | 82.80th | v4 (v2025.03.14) |
| Mar 17, 2025 | 2.82% (0.02817) | 85.21th | v4 (v2025.03.14) |
| Dec 17, 2024 | 61.91% (0.61908) | 97.97th | v3 (v2023.03.01) |
| Oct 21, 2023 | 43.41% (0.43410) | 96.93th | v3 (v2023.03.01) |
| Sep 13, 2023 | 23.99% (0.23993) | 96.00th | v3 (v2023.03.01) |
| Aug 6, 2023 | 6.19% (0.06192) | 92.60th | v3 (v2023.03.01) |
| Jun 29, 2023 | 4.90% (0.04895) | 91.62th | v3 (v2023.03.01) |
| May 22, 2023 | 4.07% (0.04068) | 90.82th | v3 (v2023.03.01) |
| Mar 7, 2023 | 3.72% (0.03717) | 90.35th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.36% (0.04358) | 88.02th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.36% (0.04358) | 86.83th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.36% (0.04358) | 70.59th | v2 (v2022.01.01) |
References (53)
- http://secunia.com/advisories/22133 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22134 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22135 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22147 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22149 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22151 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22153 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22154 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22157 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22168 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22169 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22170 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://securityreason.com/securityalert/1658 third-party-advisoryx_refsource_SREASON
- http://www.osvdb.org/29299 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/29300 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/29301 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/29302 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/29303 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/29304 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/29305 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/29306 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/29307 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/29308 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/29309 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/29310 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/29311 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/archive/1/447184/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/447185/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/447186/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/447187/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/447188/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/447190/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/447192/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/447193/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/447194/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/447201/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/447207/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/447209/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/447213/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.vupen.com/english/advisories/2006/3803 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2006/3804 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2006/3805 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2006/3806 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2006/3807 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2006/3808 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2006/3809 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2006/3810 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2006/3811 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2006/3812 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2006/3813 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2006/3814 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2006/3815 vdb-entryx_refsource_VUPENVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29220 vdb-entryx_refsource_XF
Change history (0)
No recorded changes yet.