Vulnerability record · CVE-2007-2939 · published 31 May 2007
CVE-2007-2939: Mazen's PHP Chat remote file inclusion in PEAR include files
MMazens Php Chat · Mazens Php Chat
Mazen's PHP Chat 3.0.0 contains multiple PHP remote file inclusion flaws in include/pear/ITX.php, IT_Error.php and IT.php, where the basepath parameter is used to include a remote file. An attacker who controls that parameter can cause the application to fetch and execute arbitrary PHP code from a remote URL.
Description
Multiple PHP remote file inclusion vulnerabilities in Mazen's PHP Chat 3.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the basepath parameter to (1) ITX.php, (2) IT_Error.php, or (3) IT.php in include/pear/.
AV:N/AC:M/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote unauthenticated code execution with public exploit code and a very high EPSS score, though the CVSS 2.0 base score is only 6.8 and the product is old and likely rare.
What it is
Mazen's PHP Chat 3.0.0 contains multiple PHP remote file inclusion flaws in include/pear/ITX.php, IT_Error.php and IT.php, where the basepath parameter is used to include a remote file. An attacker who controls that parameter can cause the application to fetch and execute arbitrary PHP code from a remote URL.
Impact
Successful exploitation gives the attacker arbitrary PHP code execution in the context of the web server, which can lead to full compromise of the chat application and its host. The CVSS 2.0 vector rates partial confidentiality, integrity and availability impact.
Attack surface
Reachable over the network via HTTP requests to the affected include/pear/ scripts with a crafted basepath parameter; no authentication is required per the CVSS vector (Au:N). No user interaction is indicated in the record.
Exploitation
Not listed in CISA KEV, but EPSS is high at 0.64028 (99.186th percentile) and a public Exploit-DB entry (3994) exists, indicating exploit code is publicly available.
What to do
- Upgrade or remove Mazen's PHP Chat 3.0.0; no fixed version is stated in this record, so treat the product as unsupported and migrate to a maintained alternative.
- Disable allow_url_include and allow_url_fopen in PHP to block remote file inclusion.
- Restrict outbound HTTP from the web server so it cannot fetch attacker-controlled PHP.
- Block or remove direct web access to include/pear/ scripts such as ITX.php, IT_Error.php and IT.php.
- Apply WAF rules rejecting requests with URL values in the basepath parameter.
Detection
- Search web logs for requests to include/pear/ITX.php, IT_Error.php or IT.php containing basepath with an http:// or https:// value.
- Monitor for outbound HTTP requests originating from the web server process to unfamiliar hosts.
- Alert on PHP errors or unexpected file inclusion warnings referencing remote URLs.
- Review server-side file changes or new PHP files that appear after suspicious include requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-2939 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2007-2939), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.