Vulnerability record · CVE-2007-4757 · published 8 September 2007
CVE-2007-4757: phpMytourney menu.php remote file inclusion allows PHP code execution
PPhpmytourney · Phpmytourney
phpMytourney's menu.php passes the functions_file parameter to a PHP include without validating it, so a remote attacker can supply a URL to an external file. Because the included file is executed as PHP, this becomes arbitrary code execution on the server. The flaw is a classic remote file inclusion in an old PHP application.
Description
PHP remote file inclusion vulnerability in menu.php in phpMytourney allows remote attackers to execute arbitrary PHP code via a URL in the functions_file parameter.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote code execution with public exploit code and very high EPSS, though the product is old and not in KEV.
What it is
phpMytourney's menu.php passes the functions_file parameter to a PHP include without validating it, so a remote attacker can supply a URL to an external file. Because the included file is executed as PHP, this becomes arbitrary code execution on the server. The flaw is a classic remote file inclusion in an old PHP application.
Impact
An attacker gains remote code execution in the web server's context, allowing arbitrary PHP to run, data theft, and further compromise of the host. No privileges are needed beyond network reachability.
Attack surface
Reached over the network via HTTP requests to menu.php with a crafted functions_file parameter, per the AV:N/AC:L/Au:N vector. No authentication or user interaction is required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.64693 (99.2nd percentile) and references include an Exploit tag plus an Exploit-DB entry, indicating public exploit code exists.
What to do
- Patch or upgrade phpMytourney to a version that validates the functions_file parameter; if no fixed release exists, remove or disable the affected menu.php.
- Block remote file inclusion by setting allow_url_include=Off and allow_url_fopen=Off in php.ini.
- Restrict PHP include paths and validate functions_file against a strict allowlist of local files.
- Deploy WAF rules to block URL values in functions_file and other include parameters.
- Isolate the application behind network controls and remove it if it is no longer maintained.
Detection
- Search web logs for requests to menu.php with functions_file containing http://, https://, ftp://, or other URL schemes.
- Alert on outbound HTTP requests from the web server to unfamiliar hosts, which may indicate remote include fetches.
- Monitor for unexpected PHP file creation or modification in web-accessible directories.
- Review server logs for POST or GET parameters carrying remote URLs to PHP scripts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-4757 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-4757), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.