Vulnerability record · CVE-2007-3371 · published 22 June 2007
CVE-2007-3371: Powl htmledit.php remote file inclusion allows PHP code execution
PPowl · Powl
Powl 0.94 contains a remote file inclusion flaw in plugins/widgets/htmledit/htmledit.php. The _POWL[installPath] parameter is used to include a remote file without validation, letting an attacker supply a URL to attacker-controlled PHP code. This matters because successful exploitation runs arbitrary PHP in the context of the web server.
Description
PHP remote file inclusion vulnerability in plugins/widgets/htmledit/htmledit.php in Powl 0.94 allows remote attackers to execute arbitrary PHP code via a URL in the _POWL[installPath] parameter.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote code execution with public exploit code and a very high EPSS score, though no KEV listing and an old, likely retired product temper the rating.
What it is
Powl 0.94 contains a remote file inclusion flaw in plugins/widgets/htmledit/htmledit.php. The _POWL[installPath] parameter is used to include a remote file without validation, letting an attacker supply a URL to attacker-controlled PHP code. This matters because successful exploitation runs arbitrary PHP in the context of the web server.
Impact
An attacker gains remote code execution as the web server user, which can lead to full compromise of the Powl application and its host.
Attack surface
The flaw is reachable over the network through the htmledit.php script with no authentication required, per the CVSS vector AV:N/AC:L/Au:N. No user interaction is indicated by the record.
Exploitation
CISA KEV does not list this CVE, but EPSS is high at 0.71184 (99.377th percentile) and a public Exploit-DB entry (4090) exists, indicating exploit code is publicly available.
What to do
- Upgrade or patch Powl beyond the affected 0.94 release; the record does not name a fixed version, so confirm with the vendor.
- If patching is not possible, remove or disable the plugins/widgets/htmledit/htmledit.php script.
- Set PHP allow_url_include to Off and allow_url_fopen to Off to block remote file inclusion.
- Restrict outbound network access from the web server to limit retrieval of remote payloads.
- Deploy a WAF rule blocking URL values in the _POWL[installPath] parameter.
Detection
- Search web logs for requests to plugins/widgets/htmledit/htmledit.php with URL values in _POWL[installPath].
- Monitor for outbound HTTP requests from the web server to external hosts shortly after htmledit.php access.
- Alert on unexpected PHP file creation or modification under the web root.
- Review PHP error logs for include or fopen failures referencing remote URLs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-3371 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2007-3371), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.