Vulnerability record · CVE-2007-1697 · published 27 March 2007
CVE-2007-1697: Philex header.inc.php CssFile parameter remote file inclusion
Philex · Philex
Philex 0.2.3 and earlier contains a remote file inclusion flaw in header.inc.php, where the CssFile parameter is used without validation. An attacker can supply a URL to a remote file, causing the application to include and execute arbitrary PHP code.
Description
PHP remote file inclusion vulnerability in header.inc.php in Philex 0.2.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CssFile parameter.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score is 10.0 with network reachability, no authentication, and complete confidentiality, integrity, and availability impact, and public exploit code exists.
What it is
Philex 0.2.3 and earlier contains a remote file inclusion flaw in header.inc.php, where the CssFile parameter is used without validation. An attacker can supply a URL to a remote file, causing the application to include and execute arbitrary PHP code.
Impact
Successful exploitation gives the attacker arbitrary PHP code execution in the context of the web server, leading to full compromise of the application and potentially the host.
Attack surface
The flaw is reachable over the network through HTTP requests to header.inc.php with a crafted CssFile parameter. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/Au:N).
Exploitation
Public exploit references exist (SecurityFocus BID 23111 tagged Exploit, Exploit-DB 3552), and EPSS is 0.73005 (99.4th percentile), indicating high likelihood of exploitation activity. It is not listed in CISA KEV.
What to do
- Upgrade Philex to a version later than 0.2.3 if one is available; the record does not name a fixed version.
- If upgrade is not possible, disable or remove header.inc.php or block access to it at the web server.
- Configure PHP with allow_url_include=Off and allow_url_fopen=Off to prevent remote file inclusion.
- Validate and whitelist the CssFile parameter so only local, expected paths are accepted.
- Restrict outbound network access from the web server to reduce the ability to fetch attacker-controlled files.
Detection
- Search web server and proxy logs for requests to header.inc.php with CssFile values containing http://, https://, ftp://, or other URL schemes.
- Monitor for unexpected outbound HTTP requests from the web server to external hosts.
- Look for newly created or modified PHP files in web-accessible directories that may indicate dropped payloads.
- Alert on PHP include or require errors referencing remote URLs in application logs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-1697 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-1697), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.