← Vulnerability feed

Vulnerability record · CVE-2007-3228 · published 14 June 2007

CVE-2007-3228: Sitellite CMS PHP remote file inclusion in PhpDocumentor test script

SSimian Systems Inc · Sitellite Cms

Sitellite CMS 4.2.12 and earlier ships a PhpDocumentor test file (bug-559668.php) that passes the FORUM[LIB] parameter into a PHP include, allowing remote file inclusion. An attacker who can reach that file can cause arbitrary PHP code from a remote URL to execute. The record notes that access to the PhpDocumentor directory tree is blocked by .htaccess by default, so the flaw is only reachable where that protection is missing or overridden.

6.8 CVSS 2.0 Medium EPSS 67% · top 0.7%
6.8CVSS 2.0 base score
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

PHP remote file inclusion vulnerability in saf/lib/PEAR/PhpDocumentor/Documentation/tests/bug-559668.php in Sitellite CMS 4.2.12 and earlier might allow remote attackers to execute arbitrary PHP code via a URL in the FORUM[LIB] parameter. NOTE: by default, access to the PhpDocumentor directory tree is blocked by .htaccess.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote code execution with public exploit code and very high EPSS, though the default .htaccess block and the age of the product reduce real-world exposure.

What it is

Sitellite CMS 4.2.12 and earlier ships a PhpDocumentor test file (bug-559668.php) that passes the FORUM[LIB] parameter into a PHP include, allowing remote file inclusion. An attacker who can reach that file can cause arbitrary PHP code from a remote URL to execute. The record notes that access to the PhpDocumentor directory tree is blocked by .htaccess by default, so the flaw is only reachable where that protection is missing or overridden.

Impact

Successful exploitation gives the attacker remote code execution in the context of the web server, enabling full compromise of the CMS host. The default .htaccess block limits this to misconfigured or non-Apache deployments.

Attack surface

Reached over the network via an HTTP request to the PhpDocumentor test script with a crafted FORUM[LIB] URL; no authentication or user interaction is required per the CVSS vector (AV:N/AC:M/Au:N). The default .htaccess restriction on the PhpDocumentor directory is the main barrier.

Exploitation

Not listed in CISA KEV and no ransomware association is recorded, but EPSS is high (0.67463, 99.27th percentile) and a public Exploit-DB entry (4071) exists, indicating known public exploit code.

What to do

  • Upgrade Sitellite CMS past 4.2.12 or apply the vendor fix for the PhpDocumentor test script.
  • Remove or delete the PhpDocumentor Documentation/tests directory from production deployments.
  • Verify the .htaccess deny rule protecting the PhpDocumentor tree is present and enforced, and apply equivalent restrictions on non-Apache servers.
  • Disable allow_url_include and allow_url_fopen in PHP where feasible to blunt remote file inclusion.
  • Restrict outbound HTTP from the web server to limit retrieval of attacker-hosted payloads.

Detection

  • Search web logs for requests to saf/lib/PEAR/PhpDocumentor/Documentation/tests/bug-559668.php, especially with FORUM[LIB] parameters containing http:// or https:// URLs.
  • Alert on PHP include or fopen activity reaching external hosts from the web server process.
  • Monitor for unexpected PHP files or webshells written under the web root following requests to PhpDocumentor paths.
  • Audit the web root for the presence of the PhpDocumentor tests directory and confirm .htaccess coverage.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-3228 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2007-3228), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.