← Vulnerability feed

Vulnerability record · CVE-2007-2707 · published 16 May 2007

CVE-2007-2707: Linksnet Newsfeed PHP remote file inclusion in linksnet_linkslog_rss.php

Linksnet · Newsfeed

Linksnet Newsfeed 1.0 contains a PHP remote file inclusion flaw in linksnet_linkslog_rss.php. The dirpath_linksnet_newsfeed parameter is used to include a remote file without validation, letting an attacker supply a URL to attacker-controlled PHP code. This matters because successful inclusion results in arbitrary PHP code execution on the web server.

6.8 CVSS 2.0 Medium EPSS 68% · top 0.7%
6.8CVSS 2.0 base score
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

PHP remote file inclusion vulnerability in linksnet_linkslog_rss.php in Linksnet Newsfeed 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the dirpath_linksnet_newsfeed parameter.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated remote code execution with public exploit code and very high EPSS, though the product is old and not in KEV.

What it is

Linksnet Newsfeed 1.0 contains a PHP remote file inclusion flaw in linksnet_linkslog_rss.php. The dirpath_linksnet_newsfeed parameter is used to include a remote file without validation, letting an attacker supply a URL to attacker-controlled PHP code. This matters because successful inclusion results in arbitrary PHP code execution on the web server.

Impact

An attacker can execute arbitrary PHP code in the context of the web server, leading to full compromise of the application and potentially the host. This can expose data, allow web shell placement, and enable lateral movement depending on server permissions.

Attack surface

The flaw is reachable over the network through HTTP requests to linksnet_linkslog_rss.php, with the dirpath_linksnet_newsfeed parameter carrying a remote URL. No authentication is required, and no user interaction is indicated by the description or vector.

Exploitation

The record is not listed in CISA KEV, but EPSS is high at 0.68011 (99.288th percentile), and a public Exploit-DB entry (3923) exists, indicating exploit code is available. No ransomware group usage is documented.

What to do

  • Apply the vendor fix or upgrade from Linksnet Newsfeed 1.0 if an update is available; the record does not name a fixed version.
  • Disable or remove linksnet_linkslog_rss.php if the RSS feature is not required.
  • Set allow_url_include=Off and allow_url_fopen=Off in PHP configuration to block remote file inclusion.
  • Restrict outbound network access from the web server so it cannot fetch attacker-controlled URLs.
  • Deploy a WAF rule that blocks URL-like values in the dirpath_linksnet_newsfeed parameter.

Detection

  • Search web logs for requests to linksnet_linkslog_rss.php with dirpath_linksnet_newsfeed containing http:// or https:// URLs.
  • Monitor for unexpected outbound HTTP requests from the web server to external hosts.
  • Look for newly created or modified PHP files in web-accessible directories that could be dropped via included remote code.
  • Alert on PHP include or require errors referencing remote URLs in application or server logs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-2707 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2007-2707), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.