← Vulnerability feed

Vulnerability record · CVE-2007-2937 · published 31 May 2007

CVE-2007-2937: TROforum admin.php site_url parameter remote file inclusion

TTroforum · Troforum

TROforum 0.1 contains a remote file inclusion flaw in admin/admin.php where the site_url parameter is used without validation. An attacker can supply a URL to a remote file, causing the server to include and execute arbitrary PHP code. This is a high-severity issue because it leads directly to remote code execution on the web server.

7.5 CVSS 2.0 High EPSS 64% · top 0.8%
7.5CVSS 2.0 base score
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

PHP remote file inclusion vulnerability in admin/admin.php in TROforum 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the site_url parameter.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityThe flaw allows unauthenticated remote code execution, public exploit code exists, and EPSS is very high, though no KEV listing or ransomware association is present.

What it is

TROforum 0.1 contains a remote file inclusion flaw in admin/admin.php where the site_url parameter is used without validation. An attacker can supply a URL to a remote file, causing the server to include and execute arbitrary PHP code. This is a high-severity issue because it leads directly to remote code execution on the web server.

Impact

An unauthenticated attacker can execute arbitrary PHP code with the privileges of the web server, enabling full compromise of the application and potentially the host. This can lead to data theft, web shell deployment, or use of the server as a pivot point.

Attack surface

The flaw is reachable over the network via HTTP requests to admin/admin.php with a crafted site_url parameter. No authentication or user interaction is required per the CVSS vector AV:N/AC:L/Au:N.

Exploitation

No CISA KEV listing is present, but EPSS is 0.64362 (99.195th percentile) and a public Exploit-DB entry (3995) exists, indicating exploit code is publicly available and exploitation is likely.

What to do

  • Apply the vendor patch or upgrade TROforum to a fixed version if one exists; if no patch is available, remove or disable the vulnerable admin/admin.php component.
  • Disable PHP allow_url_include and allow_url_fopen where possible to block remote file inclusion.
  • Restrict access to the admin directory by IP allowlisting or HTTP authentication so only trusted administrators can reach it.
  • Deploy a web application firewall rule to block requests containing URL schemes (http, https, ftp) in the site_url parameter.
  • Run the web server with least privilege and isolate it from sensitive internal systems.

Detection

  • Search web server access logs for requests to /admin/admin.php with site_url containing http://, https://, or ftp://.
  • Monitor for unexpected outbound HTTP connections from the web server to external hosts following admin.php requests.
  • Use file integrity monitoring to detect new or modified PHP files in the web root, which may indicate a dropped web shell.
  • Review PHP error logs for include or fopen warnings referencing remote URLs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-2937 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2007-2937), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.