CVE-2007-2736: Achievo

High severity, CVSS 10.0. EPSS: 4.1% chance of exploitation in the next 30 days.

PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config_atkroot parameter.

Affected products

  • Achievo Achievo: version 1.1.0 only

Published 2007-05-17. Last modified 2026-06-16.