Vulnerability record · CVE-2007-3220 · published 14 June 2007
CVE-2007-3220: XOOPS Cjay Content module PHP remote file inclusion
Xoops · Cjay Content Module
The Cjay Content 3 module for XOOPS passes the spaw_root parameter to a PHP include in admin/editor2/spaw_control.class.php without validation, allowing remote file inclusion. An attacker can point that parameter at a remote file and have arbitrary PHP code executed by the web server. The record notes this may be a duplicate of CVE-2006-4656.
Description
PHP remote file inclusion vulnerability in admin/editor2/spaw_control.class.php in the Cjay Content 3 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this may be a duplicate of CVE-2006-4656.
AV:N/AC:M/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote unauthenticated code execution with public exploit code and very high EPSS, though the CVSS 2.0 score is only 6.8 and the record is old and possibly a duplicate.
What it is
The Cjay Content 3 module for XOOPS passes the spaw_root parameter to a PHP include in admin/editor2/spaw_control.class.php without validation, allowing remote file inclusion. An attacker can point that parameter at a remote file and have arbitrary PHP code executed by the web server. The record notes this may be a duplicate of CVE-2006-4656.
Impact
Successful exploitation gives the attacker arbitrary PHP code execution in the context of the web server, which can lead to full compromise of the XOOPS site and its host.
Attack surface
Reachable over the network through the admin/editor2/spaw_control.class.php script via the spaw_root parameter; the CVSS vector (AV:N/AC:M/Au:N) indicates no authentication is required, though the description does not state whether user interaction is needed.
Exploitation
Not listed in CISA KEV, but EPSS is 0.62746 (99.156th percentile) and a public Exploit-DB entry (4070) exists, indicating known public exploit code.
What to do
- Apply the vendor fix or update the Cjay Content module/XOOPS installation to a version that validates spaw_root.
- If no patch is available, remove or disable the Cjay Content module, especially the admin/editor2/spaw_control.class.php script.
- Set allow_url_include=Off and allow_url_fopen=Off in PHP configuration to block remote file inclusion.
- Restrict network access to XOOPS administrative paths and place the site behind a WAF rule blocking URL parameters that reference remote hosts.
Detection
- Search web logs for requests to admin/editor2/spaw_control.class.php with spaw_root values containing http://, https://, ftp:// or other remote schemes.
- Monitor for unexpected outbound HTTP requests from the web server process and for newly created PHP files in web-accessible directories.
- Alert on PHP include/require errors or unusual child processes spawned by the web server user.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-3220 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2007-3220), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.