← Vulnerability feed

Vulnerability record · CVE-2007-3371 · published 22 June 2007

CVE-2007-3371: Powl htmledit.php remote file inclusion allows PHP code execution

PPowl · Powl

Powl 0.94 contains a remote file inclusion flaw in plugins/widgets/htmledit/htmledit.php. The _POWL[installPath] parameter is used to include a remote file without validation, letting an attacker supply a URL to attacker-controlled PHP code. This matters because successful exploitation runs arbitrary PHP in the context of the web server.

7.5 CVSS 2.0 High EPSS 71% · top 0.6%
7.5CVSS 2.0 base score
71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

PHP remote file inclusion vulnerability in plugins/widgets/htmledit/htmledit.php in Powl 0.94 allows remote attackers to execute arbitrary PHP code via a URL in the _POWL[installPath] parameter.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated remote code execution with public exploit code and a very high EPSS score, though no KEV listing and an old, likely retired product temper the rating.

What it is

Powl 0.94 contains a remote file inclusion flaw in plugins/widgets/htmledit/htmledit.php. The _POWL[installPath] parameter is used to include a remote file without validation, letting an attacker supply a URL to attacker-controlled PHP code. This matters because successful exploitation runs arbitrary PHP in the context of the web server.

Impact

An attacker gains remote code execution as the web server user, which can lead to full compromise of the Powl application and its host.

Attack surface

The flaw is reachable over the network through the htmledit.php script with no authentication required, per the CVSS vector AV:N/AC:L/Au:N. No user interaction is indicated by the record.

Exploitation

CISA KEV does not list this CVE, but EPSS is high at 0.71184 (99.377th percentile) and a public Exploit-DB entry (4090) exists, indicating exploit code is publicly available.

What to do

  • Upgrade or patch Powl beyond the affected 0.94 release; the record does not name a fixed version, so confirm with the vendor.
  • If patching is not possible, remove or disable the plugins/widgets/htmledit/htmledit.php script.
  • Set PHP allow_url_include to Off and allow_url_fopen to Off to block remote file inclusion.
  • Restrict outbound network access from the web server to limit retrieval of remote payloads.
  • Deploy a WAF rule blocking URL values in the _POWL[installPath] parameter.

Detection

  • Search web logs for requests to plugins/widgets/htmledit/htmledit.php with URL values in _POWL[installPath].
  • Monitor for outbound HTTP requests from the web server to external hosts shortly after htmledit.php access.
  • Alert on unexpected PHP file creation or modification under the web root.
  • Review PHP error logs for include or fopen failures referencing remote URLs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-3371 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2007-3371), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.