Vulnerability record · CVE-2007-5099 · published 26 September 2007
CVE-2007-5099: Helplink show.php file parameter remote file inclusion
DDavid Watters · Helplink
Helplink 0.1.0 contains a remote file inclusion flaw in show.php: the file parameter is used to include a remote URL without validation. An attacker can point that parameter at a server they control and cause the application to execute arbitrary PHP code. The record does not list affected versions beyond 0.1.0.
Description
PHP remote file inclusion vulnerability in show.php in David Watters Helplink 0.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote code execution with a public exploit and very high EPSS score, though the product is old and niche and no KEV listing is present.
What it is
Helplink 0.1.0 contains a remote file inclusion flaw in show.php: the file parameter is used to include a remote URL without validation. An attacker can point that parameter at a server they control and cause the application to execute arbitrary PHP code. The record does not list affected versions beyond 0.1.0.
Impact
Successful exploitation gives the attacker arbitrary PHP code execution in the context of the web server, which typically leads to full compromise of the application and its data. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as partial.
Attack surface
Reachable over the network through HTTP requests to show.php with a crafted file parameter; no authentication is required per the AV:N/AC:L/Au:N vector. No user interaction is indicated.
Exploitation
CISA KEV does not list this CVE, but EPSS is 0.52962 (98.9th percentile) and a public Exploit-DB entry (4448) exists, so exploitation is feasible and likely observed in scanning activity. The record does not state whether exploitation has been confirmed in the wild.
What to do
- Upgrade or remove Helplink 0.1.0; the record names no fixed version, so confirm vendor status before relying on a patch.
- Disable allow_url_include and allow_url_fopen in PHP where the application does not require remote includes.
- Validate and whitelist the file parameter in show.php so only local, expected files can be included.
- Restrict outbound HTTP from the web server to block inclusion of attacker-hosted payloads.
- If the product is unsupported, retire it or isolate it behind a reverse proxy with strict request filtering.
Detection
- Search web logs for requests to show.php with a file parameter containing http:// or https:// or other remote schemes.
- Alert on PHP processes making outbound HTTP connections shortly after a show.php request.
- Monitor for unexpected PHP files or webshell-like content written under the web root.
- Review IDS/IPS signatures for remote file inclusion patterns targeting show.php.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-5099 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-5099), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.