CVE-2007-4757
Phpmytourney - Improper Input Validation
Title source: ruleDescription
PHP remote file inclusion vulnerability in menu.php in phpMytourney allows remote attackers to execute arbitrary PHP code via a URL in the functions_file parameter.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by S.W.A.T. · textwebappsphp
https://www.exploit-db.com/exploits/4368
References (5)
Scores
EPSS
0.7484
EPSS Percentile
98.9%
Details
CWE
CWE-20
Status
published
Products (1)
phpmytourney/phpmytourney
Published
Sep 08, 2007
Tracked Since
Feb 18, 2026