Vulnerability record · CVE-2007-2545 · published 9 May 2007
CVE-2007-2545: Persism CMS system[path] parameter remote file inclusion
PPersism Cms · Persism Cms
Persism CMS 0.9.2 and earlier pass the system[path] parameter without sanitization in ten module scripts, allowing an attacker to include a remote file. Because the included file is executed as PHP, this yields arbitrary code execution on the server. The flaw is trivially reachable over HTTP and requires no authentication.
Description
Multiple PHP remote file inclusion vulnerabilities in Persism CMS 0.9.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the system[path] parameter to (1) blocks/headerfile.php, (2) files/blocks/latest_files.php, (3) filters/headerfile.php, (4) forums/blocks/latest_posts.php, (5) groups/headerfile.php, (6) links/blocks/links.php, (7) menu/headerfile.php, (8) news/blocks/latest_news.php, (9) settings/headerfile.php, or (10) users/headerfile.php, in modules/.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote code execution with public exploit code and very high EPSS, though the product is old and not in KEV.
What it is
Persism CMS 0.9.2 and earlier pass the system[path] parameter without sanitization in ten module scripts, allowing an attacker to include a remote file. Because the included file is executed as PHP, this yields arbitrary code execution on the server. The flaw is trivially reachable over HTTP and requires no authentication.
Impact
An unauthenticated attacker can execute arbitrary PHP code on the web server, leading to full compromise of the application and potentially the host. This can expose data, allow persistence, and pivot into the internal network.
Attack surface
Reached over the network via HTTP requests to the listed module scripts (for example blocks/headerfile.php, forums/blocks/latest_posts.php) with a crafted system[path] value. No authentication or user interaction is required, as reflected by the AV:N/AC:L/Au:N vector.
Exploitation
Public exploit code exists (SecurityFocus BID 23828 tagged Exploit and Exploit-DB 3853), and EPSS is 0.68754 (99.3rd percentile), indicating high likelihood of exploitation. It is not listed in CISA KEV.
What to do
- Upgrade Persism CMS beyond 0.9.2 or apply the vendor fix if available; if no patch exists, retire or replace the product.
- Block remote file inclusion by disabling allow_url_include and allow_url_fopen in PHP where feasible.
- Validate and whitelist the system[path] parameter, rejecting URLs and path traversal sequences.
- Restrict outbound HTTP from the web server to prevent retrieval of attacker-hosted payloads.
- Deploy a WAF rule to block URL values in the system[path] parameter on the affected module scripts.
Detection
- Search web logs for requests to the listed module scripts with system[path] containing http:// or https://.
- Monitor for unexpected outbound HTTP connections from the web server to unknown hosts.
- Alert on new or modified PHP files in the web root that do not match deployment baselines.
- Review PHP error logs for include or fopen warnings referencing remote URLs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-2545 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2007-2545), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.