Vulnerability record · CVE-2007-4834 · published 12 September 2007
CVE-2007-4834: phpRealty MGR parameter remote file inclusion in admin scripts
Phprealty · Phprealty
phpRealty 0.02 passes the MGR parameter from index.php, p_ins.php and u_ins.php in manager/admin/ into a PHP include without validation, allowing remote file inclusion. An attacker can point MGR at a remote file and have arbitrary PHP code executed by the server. The flaw is a classic code injection issue in an old, likely unmaintained product.
Description
Multiple PHP remote file inclusion vulnerabilities in phpRealty 0.02 allow remote attackers to execute arbitrary PHP code via a URL in the MGR parameter to (1) index.php, (2) p_ins.php, and (3) u_ins.php in manager/admin/.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote code execution with public exploit code and very high EPSS, though the product is old and likely low prevalence.
What it is
phpRealty 0.02 passes the MGR parameter from index.php, p_ins.php and u_ins.php in manager/admin/ into a PHP include without validation, allowing remote file inclusion. An attacker can point MGR at a remote file and have arbitrary PHP code executed by the server. The flaw is a classic code injection issue in an old, likely unmaintained product.
Impact
An unauthenticated attacker gains remote code execution in the web server context, which can lead to full compromise of the application and its data.
Attack surface
Reachable over the network via HTTP requests to the three manager/admin/ scripts with a crafted MGR parameter; no authentication or user interaction is required per the CVSS vector AV:N/AC:L/Au:N.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.585, 99th percentile) and a public Exploit-DB entry (4387) exists, indicating exploit code is available.
What to do
- Apply the vendor fix or upgrade phpRealty if a patched release exists; the record does not name a fixed version.
- If no patch is available, remove or restrict access to manager/admin/ scripts and disable allow_url_include and allow_url_fopen in PHP.
- Validate and whitelist the MGR parameter, rejecting URLs and path traversal sequences.
- Run the application with least privilege and isolate it from sensitive internal systems.
Detection
- Search web logs for requests to manager/admin/index.php, p_ins.php or u_ins.php with MGR values containing http://, https:// or ftp://.
- Monitor for outbound HTTP requests from the web server to unfamiliar hosts, which may indicate remote include fetches.
- Look for unexpected PHP files or webshells written under the web root and for anomalous child processes spawned by the web server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-4834 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-4834), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.