Vulnerability record · CVE-2007-2707 · published 16 May 2007
CVE-2007-2707: Linksnet Newsfeed PHP remote file inclusion in linksnet_linkslog_rss.php
Linksnet · Newsfeed
Linksnet Newsfeed 1.0 contains a PHP remote file inclusion flaw in linksnet_linkslog_rss.php. The dirpath_linksnet_newsfeed parameter is used to include a remote file without validation, letting an attacker supply a URL to attacker-controlled PHP code. This matters because successful inclusion results in arbitrary PHP code execution on the web server.
Description
PHP remote file inclusion vulnerability in linksnet_linkslog_rss.php in Linksnet Newsfeed 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the dirpath_linksnet_newsfeed parameter.
AV:N/AC:M/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote code execution with public exploit code and very high EPSS, though the product is old and not in KEV.
What it is
Linksnet Newsfeed 1.0 contains a PHP remote file inclusion flaw in linksnet_linkslog_rss.php. The dirpath_linksnet_newsfeed parameter is used to include a remote file without validation, letting an attacker supply a URL to attacker-controlled PHP code. This matters because successful inclusion results in arbitrary PHP code execution on the web server.
Impact
An attacker can execute arbitrary PHP code in the context of the web server, leading to full compromise of the application and potentially the host. This can expose data, allow web shell placement, and enable lateral movement depending on server permissions.
Attack surface
The flaw is reachable over the network through HTTP requests to linksnet_linkslog_rss.php, with the dirpath_linksnet_newsfeed parameter carrying a remote URL. No authentication is required, and no user interaction is indicated by the description or vector.
Exploitation
The record is not listed in CISA KEV, but EPSS is high at 0.68011 (99.288th percentile), and a public Exploit-DB entry (3923) exists, indicating exploit code is available. No ransomware group usage is documented.
What to do
- Apply the vendor fix or upgrade from Linksnet Newsfeed 1.0 if an update is available; the record does not name a fixed version.
- Disable or remove linksnet_linkslog_rss.php if the RSS feature is not required.
- Set allow_url_include=Off and allow_url_fopen=Off in PHP configuration to block remote file inclusion.
- Restrict outbound network access from the web server so it cannot fetch attacker-controlled URLs.
- Deploy a WAF rule that blocks URL-like values in the dirpath_linksnet_newsfeed parameter.
Detection
- Search web logs for requests to linksnet_linkslog_rss.php with dirpath_linksnet_newsfeed containing http:// or https:// URLs.
- Monitor for unexpected outbound HTTP requests from the web server to external hosts.
- Look for newly created or modified PHP files in web-accessible directories that could be dropped via included remote code.
- Alert on PHP include or require errors referencing remote URLs in application or server logs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-2707 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2007-2707), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.