← Vulnerability feed

Vulnerability record · CVE-2007-2545 · published 9 May 2007

CVE-2007-2545: Persism CMS system[path] parameter remote file inclusion

PPersism Cms · Persism Cms

Persism CMS 0.9.2 and earlier pass the system[path] parameter without sanitization in ten module scripts, allowing an attacker to include a remote file. Because the included file is executed as PHP, this yields arbitrary code execution on the server. The flaw is trivially reachable over HTTP and requires no authentication.

7.5 CVSS 2.0 High EPSS 69% · top 0.7%
7.5CVSS 2.0 base score
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
28References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple PHP remote file inclusion vulnerabilities in Persism CMS 0.9.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the system[path] parameter to (1) blocks/headerfile.php, (2) files/blocks/latest_files.php, (3) filters/headerfile.php, (4) forums/blocks/latest_posts.php, (5) groups/headerfile.php, (6) links/blocks/links.php, (7) menu/headerfile.php, (8) news/blocks/latest_news.php, (9) settings/headerfile.php, or (10) users/headerfile.php, in modules/.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityUnauthenticated remote code execution with public exploit code and very high EPSS, though the product is old and not in KEV.

What it is

Persism CMS 0.9.2 and earlier pass the system[path] parameter without sanitization in ten module scripts, allowing an attacker to include a remote file. Because the included file is executed as PHP, this yields arbitrary code execution on the server. The flaw is trivially reachable over HTTP and requires no authentication.

Impact

An unauthenticated attacker can execute arbitrary PHP code on the web server, leading to full compromise of the application and potentially the host. This can expose data, allow persistence, and pivot into the internal network.

Attack surface

Reached over the network via HTTP requests to the listed module scripts (for example blocks/headerfile.php, forums/blocks/latest_posts.php) with a crafted system[path] value. No authentication or user interaction is required, as reflected by the AV:N/AC:L/Au:N vector.

Exploitation

Public exploit code exists (SecurityFocus BID 23828 tagged Exploit and Exploit-DB 3853), and EPSS is 0.68754 (99.3rd percentile), indicating high likelihood of exploitation. It is not listed in CISA KEV.

What to do

  • Upgrade Persism CMS beyond 0.9.2 or apply the vendor fix if available; if no patch exists, retire or replace the product.
  • Block remote file inclusion by disabling allow_url_include and allow_url_fopen in PHP where feasible.
  • Validate and whitelist the system[path] parameter, rejecting URLs and path traversal sequences.
  • Restrict outbound HTTP from the web server to prevent retrieval of attacker-hosted payloads.
  • Deploy a WAF rule to block URL values in the system[path] parameter on the affected module scripts.

Detection

  • Search web logs for requests to the listed module scripts with system[path] containing http:// or https://.
  • Monitor for unexpected outbound HTTP connections from the web server to unknown hosts.
  • Alert on new or modified PHP files in the web root that do not match deployment baselines.
  • Review PHP error logs for include or fopen warnings referencing remote URLs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-2545 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2007-2545), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.