← Vulnerability feed

Vulnerability record · CVE-2007-2607 · published 11 May 2007

CVE-2007-2607: LaVague printbar.php views_path remote file inclusion

Lavague · Lavague

LaVague 0.3 and earlier contains a remote file inclusion flaw in views/print/printbar.php, where the views_path parameter is used to include a remote file without validation. An attacker can point that parameter at a malicious URL and cause arbitrary PHP code to execute on the server. The record is old and thin, but the flaw is directly exploitable over the network with no authentication.

7.5 CVSS 2.0 High EPSS 71% · top 0.6%
7.5CVSS 2.0 base score
71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

PHP remote file inclusion vulnerability in views/print/printbar.php in LaVague 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the views_path parameter.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated remote code execution with public exploit code and very high EPSS, though the product is old and likely rare in current environments.

What it is

LaVague 0.3 and earlier contains a remote file inclusion flaw in views/print/printbar.php, where the views_path parameter is used to include a remote file without validation. An attacker can point that parameter at a malicious URL and cause arbitrary PHP code to execute on the server. The record is old and thin, but the flaw is directly exploitable over the network with no authentication.

Impact

An unauthenticated attacker can execute arbitrary PHP code in the context of the web server, leading to full compromise of the application and potentially the host.

Attack surface

Reachable over the network via HTTP requests to views/print/printbar.php with a crafted views_path parameter; no authentication or user interaction is required per the CVSS vector AV:N/AC:L/Au:N.

Exploitation

Not listed in CISA KEV, but EPSS is 0.70643 (99.36th percentile) and an Exploit-DB entry (3870) exists, indicating public exploit code and high likelihood of attempted exploitation.

What to do

  • Upgrade or remove LaVague 0.3 and earlier; no fixed version is stated in the record, so treat the product as end-of-life and migrate off it.
  • Disable allow_url_include and allow_url_fopen in PHP to block remote file inclusion.
  • Validate and whitelist the views_path parameter, rejecting any URL or path outside the expected local directory.
  • Restrict outbound network access from the web server so it cannot fetch attacker-controlled remote files.
  • Place the application behind a WAF rule that blocks URL-like values in views_path.

Detection

  • Search web logs for requests to views/print/printbar.php with views_path containing http://, https://, ftp:// or similar schemes.
  • Monitor for unexpected outbound HTTP connections from the web server to external hosts.
  • Look for new or modified PHP files in the web root and unusual child processes spawned by the web server.
  • Alert on repeated 200 responses to printbar.php from single source IPs, which may indicate scanning or exploitation attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-2607 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2007-2607), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.