Unrated severityNVD Advisory· Published Oct 1, 2007· Updated Apr 23, 2026
CVE-2007-5157
CVE-2007-5157
Description
PHP remote file inclusion vulnerability in phfito-post.php in Alex Kocharin PHP Fidonet Tosser (PhFiTo) 1.3.0 in phpFidoNode allows remote attackers to execute arbitrary PHP code via a URL in the SRC_PATH parameter to phfito-post.
Affected products
2- cpe:2.3:a:php_fidonet_tosser:php_fidonet_tosser:1.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:phpfidonode:phpfidonode:*:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5News mentions
0No linked articles in our index yet.