← Vulnerability feed

Vulnerability record · CVE-2007-4757 · published 8 September 2007

CVE-2007-4757: phpMytourney menu.php remote file inclusion allows PHP code execution

PPhpmytourney · Phpmytourney

phpMytourney's menu.php passes the functions_file parameter to a PHP include without validating it, so a remote attacker can supply a URL to an external file. Because the included file is executed as PHP, this becomes arbitrary code execution on the server. The flaw is a classic remote file inclusion in an old PHP application.

7.5 CVSS 2.0 High EPSS 65% · top 0.8% CWE-20 · Improper input validation
7.5CVSS 2.0 base score
65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

PHP remote file inclusion vulnerability in menu.php in phpMytourney allows remote attackers to execute arbitrary PHP code via a URL in the functions_file parameter.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated remote code execution with public exploit code and very high EPSS, though the product is old and not in KEV.

What it is

phpMytourney's menu.php passes the functions_file parameter to a PHP include without validating it, so a remote attacker can supply a URL to an external file. Because the included file is executed as PHP, this becomes arbitrary code execution on the server. The flaw is a classic remote file inclusion in an old PHP application.

Impact

An attacker gains remote code execution in the web server's context, allowing arbitrary PHP to run, data theft, and further compromise of the host. No privileges are needed beyond network reachability.

Attack surface

Reached over the network via HTTP requests to menu.php with a crafted functions_file parameter, per the AV:N/AC:L/Au:N vector. No authentication or user interaction is required.

Exploitation

Not listed in CISA KEV, but EPSS is 0.64693 (99.2nd percentile) and references include an Exploit tag plus an Exploit-DB entry, indicating public exploit code exists.

What to do

  • Patch or upgrade phpMytourney to a version that validates the functions_file parameter; if no fixed release exists, remove or disable the affected menu.php.
  • Block remote file inclusion by setting allow_url_include=Off and allow_url_fopen=Off in php.ini.
  • Restrict PHP include paths and validate functions_file against a strict allowlist of local files.
  • Deploy WAF rules to block URL values in functions_file and other include parameters.
  • Isolate the application behind network controls and remove it if it is no longer maintained.

Detection

  • Search web logs for requests to menu.php with functions_file containing http://, https://, ftp://, or other URL schemes.
  • Alert on outbound HTTP requests from the web server to unfamiliar hosts, which may indicate remote include fetches.
  • Monitor for unexpected PHP file creation or modification in web-accessible directories.
  • Review server logs for POST or GET parameters carrying remote URLs to PHP scripts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-4757 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.8CVE-2008-1128Phpmytourney code injection vulnerabilityPHP remote file inclusion vulnerability in tourney/index.php in phpMyTourney 2 allows remote attackers to execute arbitrary PHP code via a URL in the…EPSS 2.0%9.5CVE-2026-88771Citrix NetScaler Improper Input Validation VulnerabilityImproper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-…KEV9.5CVE-2026-93952Arista velocloud orchestrator improper input validation vulnerabilityVeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…KEVEPSS 0.90%8.8CVE-2019-1068Microsoft SQL Server improper input validation remote code executionMicrosoft SQL Server mishandles processing of internal functions, allowing an authenticated remote attacker to execute code on the database server. T…KEVEPSS 58%analysed5.9CVE-2025-68686FortiOS symbolic link patch bypass exposes sensitive informationFortiOS contains an information exposure flaw (CWE-200) that lets a remote unauthenticated attacker bypass the patch for the symbolic link persistenc…KEVEPSS 30%analysed9.3CVE-2026-12569PTC Windchill PDMlink and FlexPLM deserialization RCEPTC Windchill PDMlink and FlexPLM contain a deserialization of untrusted data flaw (also classified as improper input validation) that allows remote …KEVEPSS 46%analysed10.0CVE-2026-34910Ubiquiti UniFi OS input validation flaw allows command injectionUniFi OS devices contain an improper input validation vulnerability (CWE-20) that lets a network-reachable attacker inject and execute commands. It a…KEVEPSS 46%analysed7.2CVE-2026-6973Ivanti EPMM improper input validation enables remote code executionIvanti Endpoint Manager Mobile (EPMM) before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 contains an improper input validation flaw (CWE-20) that lets …KEVEPSS 2.5%analysed

Source: NIST National Vulnerability Database (record CVE-2007-4757), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.