← Vulnerability feed

Vulnerability record · CVE-2007-2969 · published 1 June 2007

CVE-2007-2969: WAnewsletter newsletter.php waroot parameter remote file inclusion

WWanewsletter · Wanewsletter

WAnewsletter 2.1.3 and earlier contains a remote file inclusion flaw in newsletter.php, where the waroot parameter is used to include a remote file without validation. An attacker can point waroot at a hostile URL and cause the application to execute arbitrary PHP code. The issue is remotely reachable and requires no authentication.

7.5 CVSS 2.0 High EPSS 62% · top 0.9%
7.5CVSS 2.0 base score
62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

PHP remote file inclusion vulnerability in newsletter.php in WAnewsletter 2.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the waroot parameter.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityRemote unauthenticated code execution with public exploit references and very high EPSS, though the product is old and not in KEV.

What it is

WAnewsletter 2.1.3 and earlier contains a remote file inclusion flaw in newsletter.php, where the waroot parameter is used to include a remote file without validation. An attacker can point waroot at a hostile URL and cause the application to execute arbitrary PHP code. The issue is remotely reachable and requires no authentication.

Impact

Successful exploitation gives the attacker arbitrary PHP code execution in the context of the web server, enabling full compromise of the application and potentially the host. This can lead to data theft, web shell deployment, or lateral movement from the web tier.

Attack surface

Reached over the network via HTTP requests to newsletter.php with a crafted waroot parameter; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Public exploit references exist (SecurityFocus BID 24177 tagged Exploit and Exploit-DB 4000), and EPSS is 0.61727 (99.1st percentile), indicating a high likelihood of exploitation activity. The CVE is not listed in CISA KEV.

What to do

  • Upgrade WAnewsletter beyond 2.1.3 or apply the vendor fix for the waroot parameter; if no patch is available, remove or disable newsletter.php.
  • Disable allow_url_include and allow_url_fopen in PHP to block remote file inclusion.
  • Restrict outbound HTTP from the web server and block access to newsletter.php from untrusted networks.
  • Validate and whitelist the waroot parameter against a fixed local path, rejecting any URL or path traversal input.
  • Run the web application with least privilege and isolate it from sensitive internal systems.

Detection

  • Search web logs for requests to newsletter.php with waroot containing http://, https://, ftp://, or other URL schemes.
  • Monitor for unexpected outbound HTTP connections from the web server to external hosts.
  • Alert on new PHP files or modified web content in the application directory, which may indicate a dropped web shell.
  • Review PHP error logs for include or fopen warnings referencing remote URLs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-2969 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2007-2969), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.