Vulnerability record · CVE-2007-2199 · published 24 April 2007
CVE-2007-2199: PclTar PHP Remote File Inclusion Enables Arbitrary Code Execution
CCjg Explorer Pro · Cjg Explorer Pro
The PclTar module (lib/pcltar.lib.php) versions 1.3 and 1.3.1 for the Vincent Blavet PhpConcept Library fails to properly sanitize the g_pcltar_lib_dir parameter, allowing remote file inclusion. Because this library is bundled into multiple products including Joomla! 1.5.0 Beta, N/X WCMS 4.5, CJG EXPLORER PRO 3.3, and phpSiteBackup 0.1, any of those deployments may be exposed. Successful exploitation lets an attacker run arbitrary PHP code on the server.
Description
PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vincent Blavet PhpConcept Library, as used in multiple products including (1) Joomla! 1.5.0 Beta, (2) N/X Web Content Management System (WCMS) 4.5, (3) CJG EXPLORER PRO 3.3, and (4) phpSiteBackup 0.1, allows remote attackers to execute arbitrary PHP code via a URL in the g_pcltar_lib_dir parameter.
AV:N/AC:M/Au:N/C:P/I:P/A:P
Automated analysis
high priorityAlthough the CVSS v2 score is medium (6.8), the flaw allows unauthenticated remote code execution, public exploits are available, and EPSS is very high, making it a serious risk for exposed instances.
What it is
The PclTar module (lib/pcltar.lib.php) versions 1.3 and 1.3.1 for the Vincent Blavet PhpConcept Library fails to properly sanitize the g_pcltar_lib_dir parameter, allowing remote file inclusion. Because this library is bundled into multiple products including Joomla! 1.5.0 Beta, N/X WCMS 4.5, CJG EXPLORER PRO 3.3, and phpSiteBackup 0.1, any of those deployments may be exposed. Successful exploitation lets an attacker run arbitrary PHP code on the server.
Impact
An attacker can execute arbitrary PHP code in the context of the web server, leading to full compromise of the application and potentially the underlying host. This can result in data theft, web shell installation, or use of the server as a pivot point.
Attack surface
The flaw is reachable over the network via HTTP by supplying a malicious URL in the g_pcltar_lib_dir parameter; no authentication is required per the CVSS vector (AV:N/AC:M/Au:N). No user interaction is indicated.
Exploitation
CISA KEV does not list this CVE, but EPSS is high (0.469 probability, 98.8th percentile) and public exploit code exists in Exploit-DB (3781, 3915, 4111) plus an Exploit-tagged advisory, indicating active exploitation is feasible.
What to do
- Apply vendor patches or upgrade PclTar and any bundled products (Joomla!, N/X WCMS, CJG EXPLORER PRO, phpSiteBackup) to versions that fix the g_pcltar_lib_dir input handling.
- If patching is not immediately possible, remove or disable the vulnerable PclTar library files if they are not required.
- Enforce PHP configuration hardening such as allow_url_include=Off and allow_url_fopen=Off to block remote file inclusion.
- Deploy a web application firewall rule to block requests containing URL schemes or path traversal in the g_pcltar_lib_dir parameter.
- Restrict outbound network access from web servers to limit the ability to fetch remote payloads.
Detection
- Search web server access logs for requests to lib/pcltar.lib.php or pcltar.php with g_pcltar_lib_dir containing http://, https://, ftp://, or similar remote URL schemes.
- Monitor for unexpected outbound HTTP connections from the web server to external hosts following such requests.
- Use file integrity monitoring to detect new or modified PHP files in web-accessible directories that could be dropped payloads.
- Review PHP error logs for include or require failures referencing remote URLs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-2199 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-2199), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.