← Vulnerability feed

Vulnerability record · CVE-2007-2708 · published 16 May 2007

CVE-2007-2708: News-Script newsadmin.php remote file inclusion

FFeindt Computerservice · News Script

Feindt Computerservice News (News-Script) 2.0 contains a remote file inclusion flaw in newsadmin.php. The action parameter is used to build a file path without validation, so a remote attacker can supply a URL and cause the application to include and execute arbitrary PHP code. This is a full remote code execution path against an unauthenticated endpoint.

7.5 CVSS 2.0 High EPSS 63% · top 0.8%
7.5CVSS 2.0 base score
63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

PHP remote file inclusion vulnerability in newsadmin.php in Feindt Computerservice News (News-Script) 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the action parameter.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityUnauthenticated remote code execution with public exploit code and very high EPSS, though the affected product is an old niche script.

What it is

Feindt Computerservice News (News-Script) 2.0 contains a remote file inclusion flaw in newsadmin.php. The action parameter is used to build a file path without validation, so a remote attacker can supply a URL and cause the application to include and execute arbitrary PHP code. This is a full remote code execution path against an unauthenticated endpoint.

Impact

An attacker can execute arbitrary PHP code on the server, leading to web shell deployment, data theft, or full host compromise under the web server account.

Attack surface

Reachable over the network through newsadmin.php with the action parameter; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

CISA KEV does not list this CVE, but EPSS is 0.61727 (99.1st percentile) and references are tagged Exploit, indicating public exploit code exists and exploitation is likely.

What to do

  • Patch or replace News-Script 2.0; the vendor has not issued a fix in this record, so treat the product as end-of-life and migrate to a maintained alternative.
  • If the application must stay online, block remote URL inclusion by disabling allow_url_include and allow_url_fopen in PHP.
  • Restrict access to newsadmin.php to trusted administrative networks or remove it from public exposure.
  • Deploy a WAF rule that rejects requests to newsadmin.php where the action parameter contains a URL scheme such as http://, https://, ftp://, or php://.
  • Run the web service under a least-privilege account with open_basedir and disable_functions set to limit post-exploitation impact.

Detection

  • Search web logs for requests to newsadmin.php with action values containing http://, https://, ftp://, or php://.
  • Monitor for unexpected PHP files created in web-accessible directories and for outbound HTTP requests originating from the web server process.
  • Alert on PHP include or require errors referencing remote hosts in application error logs.
  • Use file integrity monitoring on the web root to catch newly written scripts or modified PHP files.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-2708 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2007-2708), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.