Vulnerability record · CVE-2007-4320 · published 14 August 2007
CVE-2007-4320: Ncaster archive.php adminfolder parameter remote file inclusion
Ncaster · Ncaster
Ncaster 1.7.2 contains a remote file inclusion flaw in admin/addons/archive/archive.php where the adminfolder parameter is used to include a remote file without validation. An attacker can point that parameter at a URL hosting malicious PHP, causing the server to fetch and execute it. This yields arbitrary code execution on the web server.
Description
PHP remote file inclusion vulnerability in admin/addons/archive/archive.php in Ncaster 1.7.2 allows remote attackers to execute arbitrary PHP code via a URL in the adminfolder parameter.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote code execution with public exploit code and very high EPSS, though the product is old and not in KEV.
What it is
Ncaster 1.7.2 contains a remote file inclusion flaw in admin/addons/archive/archive.php where the adminfolder parameter is used to include a remote file without validation. An attacker can point that parameter at a URL hosting malicious PHP, causing the server to fetch and execute it. This yields arbitrary code execution on the web server.
Impact
An attacker gains remote code execution in the context of the web server, allowing arbitrary PHP to run, data theft, and further host compromise.
Attack surface
Reachable over the network via HTTP requests to admin/addons/archive/archive.php; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.72022 (99.4th percentile) and a SecurityFocus reference is tagged Exploit, with an Exploit-DB entry present, indicating public exploit code exists.
What to do
- Patch or upgrade Ncaster beyond 1.7.2; if no fixed release exists, remove or disable admin/addons/archive/archive.php.
- Block remote file inclusion by setting allow_url_include=Off and allow_url_fopen=Off in PHP.
- Restrict access to the admin/addons directory via web server ACLs or authentication.
- Validate and whitelist the adminfolder parameter against a fixed list of local paths.
- Monitor and egress-filter outbound HTTP from the web server to prevent fetching attacker-hosted payloads.
Detection
- Search web logs for requests to admin/addons/archive/archive.php with an adminfolder parameter containing http:// or https:// URLs.
- Alert on outbound HTTP requests originating from the web server process to unfamiliar hosts.
- Look for unexpected PHP files or webshells written under the web root after such requests.
- Monitor for anomalous child processes spawned by the web server (e.g., shell commands).
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-4320 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2007-4320), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.