Vulnerability record · CVE-2007-3228 · published 14 June 2007
CVE-2007-3228: Sitellite CMS PHP remote file inclusion in PhpDocumentor test script
SSimian Systems Inc · Sitellite Cms
Sitellite CMS 4.2.12 and earlier ships a PhpDocumentor test file (bug-559668.php) that passes the FORUM[LIB] parameter into a PHP include, allowing remote file inclusion. An attacker who can reach that file can cause arbitrary PHP code from a remote URL to execute. The record notes that access to the PhpDocumentor directory tree is blocked by .htaccess by default, so the flaw is only reachable where that protection is missing or overridden.
Description
PHP remote file inclusion vulnerability in saf/lib/PEAR/PhpDocumentor/Documentation/tests/bug-559668.php in Sitellite CMS 4.2.12 and earlier might allow remote attackers to execute arbitrary PHP code via a URL in the FORUM[LIB] parameter. NOTE: by default, access to the PhpDocumentor directory tree is blocked by .htaccess.
AV:N/AC:M/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote code execution with public exploit code and very high EPSS, though the default .htaccess block and the age of the product reduce real-world exposure.
What it is
Sitellite CMS 4.2.12 and earlier ships a PhpDocumentor test file (bug-559668.php) that passes the FORUM[LIB] parameter into a PHP include, allowing remote file inclusion. An attacker who can reach that file can cause arbitrary PHP code from a remote URL to execute. The record notes that access to the PhpDocumentor directory tree is blocked by .htaccess by default, so the flaw is only reachable where that protection is missing or overridden.
Impact
Successful exploitation gives the attacker remote code execution in the context of the web server, enabling full compromise of the CMS host. The default .htaccess block limits this to misconfigured or non-Apache deployments.
Attack surface
Reached over the network via an HTTP request to the PhpDocumentor test script with a crafted FORUM[LIB] URL; no authentication or user interaction is required per the CVSS vector (AV:N/AC:M/Au:N). The default .htaccess restriction on the PhpDocumentor directory is the main barrier.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is high (0.67463, 99.27th percentile) and a public Exploit-DB entry (4071) exists, indicating known public exploit code.
What to do
- Upgrade Sitellite CMS past 4.2.12 or apply the vendor fix for the PhpDocumentor test script.
- Remove or delete the PhpDocumentor Documentation/tests directory from production deployments.
- Verify the .htaccess deny rule protecting the PhpDocumentor tree is present and enforced, and apply equivalent restrictions on non-Apache servers.
- Disable allow_url_include and allow_url_fopen in PHP where feasible to blunt remote file inclusion.
- Restrict outbound HTTP from the web server to limit retrieval of attacker-hosted payloads.
Detection
- Search web logs for requests to saf/lib/PEAR/PhpDocumentor/Documentation/tests/bug-559668.php, especially with FORUM[LIB] parameters containing http:// or https:// URLs.
- Alert on PHP include or fopen activity reaching external hosts from the web server process.
- Monitor for unexpected PHP files or webshells written under the web root following requests to PhpDocumentor paths.
- Audit the web root for the presence of the PhpDocumentor tests directory and confirm .htaccess coverage.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-3228 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2007-3228), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.