← Vulnerability feed

Vulnerability record · CVE-2007-4320 · published 14 August 2007

CVE-2007-4320: Ncaster archive.php adminfolder parameter remote file inclusion

Ncaster · Ncaster

Ncaster 1.7.2 contains a remote file inclusion flaw in admin/addons/archive/archive.php where the adminfolder parameter is used to include a remote file without validation. An attacker can point that parameter at a URL hosting malicious PHP, causing the server to fetch and execute it. This yields arbitrary code execution on the web server.

7.5 CVSS 2.0 High EPSS 72% · top 0.6%
7.5CVSS 2.0 base score
72%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

PHP remote file inclusion vulnerability in admin/addons/archive/archive.php in Ncaster 1.7.2 allows remote attackers to execute arbitrary PHP code via a URL in the adminfolder parameter.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityUnauthenticated remote code execution with public exploit code and very high EPSS, though the product is old and not in KEV.

What it is

Ncaster 1.7.2 contains a remote file inclusion flaw in admin/addons/archive/archive.php where the adminfolder parameter is used to include a remote file without validation. An attacker can point that parameter at a URL hosting malicious PHP, causing the server to fetch and execute it. This yields arbitrary code execution on the web server.

Impact

An attacker gains remote code execution in the context of the web server, allowing arbitrary PHP to run, data theft, and further host compromise.

Attack surface

Reachable over the network via HTTP requests to admin/addons/archive/archive.php; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is 0.72022 (99.4th percentile) and a SecurityFocus reference is tagged Exploit, with an Exploit-DB entry present, indicating public exploit code exists.

What to do

  • Patch or upgrade Ncaster beyond 1.7.2; if no fixed release exists, remove or disable admin/addons/archive/archive.php.
  • Block remote file inclusion by setting allow_url_include=Off and allow_url_fopen=Off in PHP.
  • Restrict access to the admin/addons directory via web server ACLs or authentication.
  • Validate and whitelist the adminfolder parameter against a fixed list of local paths.
  • Monitor and egress-filter outbound HTTP from the web server to prevent fetching attacker-hosted payloads.

Detection

  • Search web logs for requests to admin/addons/archive/archive.php with an adminfolder parameter containing http:// or https:// URLs.
  • Alert on outbound HTTP requests originating from the web server process to unfamiliar hosts.
  • Look for unexpected PHP files or webshells written under the web root after such requests.
  • Monitor for anomalous child processes spawned by the web server (e.g., shell commands).

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-4320 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2007-4320), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.