← Vulnerability feed

Vulnerability record · CVE-2007-2199 · published 24 April 2007

CVE-2007-2199: PclTar PHP Remote File Inclusion Enables Arbitrary Code Execution

CCjg Explorer Pro · Cjg Explorer Pro

The PclTar module (lib/pcltar.lib.php) versions 1.3 and 1.3.1 for the Vincent Blavet PhpConcept Library fails to properly sanitize the g_pcltar_lib_dir parameter, allowing remote file inclusion. Because this library is bundled into multiple products including Joomla! 1.5.0 Beta, N/X WCMS 4.5, CJG EXPLORER PRO 3.3, and phpSiteBackup 0.1, any of those deployments may be exposed. Successful exploitation lets an attacker run arbitrary PHP code on the server.

6.8 CVSS 2.0 Medium EPSS 47% · top 1.2% CWE-94 · Code injection
6.8CVSS 2.0 base score
47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
36References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vincent Blavet PhpConcept Library, as used in multiple products including (1) Joomla! 1.5.0 Beta, (2) N/X Web Content Management System (WCMS) 4.5, (3) CJG EXPLORER PRO 3.3, and (4) phpSiteBackup 0.1, allows remote attackers to execute arbitrary PHP code via a URL in the g_pcltar_lib_dir parameter.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityAlthough the CVSS v2 score is medium (6.8), the flaw allows unauthenticated remote code execution, public exploits are available, and EPSS is very high, making it a serious risk for exposed instances.

What it is

The PclTar module (lib/pcltar.lib.php) versions 1.3 and 1.3.1 for the Vincent Blavet PhpConcept Library fails to properly sanitize the g_pcltar_lib_dir parameter, allowing remote file inclusion. Because this library is bundled into multiple products including Joomla! 1.5.0 Beta, N/X WCMS 4.5, CJG EXPLORER PRO 3.3, and phpSiteBackup 0.1, any of those deployments may be exposed. Successful exploitation lets an attacker run arbitrary PHP code on the server.

Impact

An attacker can execute arbitrary PHP code in the context of the web server, leading to full compromise of the application and potentially the underlying host. This can result in data theft, web shell installation, or use of the server as a pivot point.

Attack surface

The flaw is reachable over the network via HTTP by supplying a malicious URL in the g_pcltar_lib_dir parameter; no authentication is required per the CVSS vector (AV:N/AC:M/Au:N). No user interaction is indicated.

Exploitation

CISA KEV does not list this CVE, but EPSS is high (0.469 probability, 98.8th percentile) and public exploit code exists in Exploit-DB (3781, 3915, 4111) plus an Exploit-tagged advisory, indicating active exploitation is feasible.

What to do

  • Apply vendor patches or upgrade PclTar and any bundled products (Joomla!, N/X WCMS, CJG EXPLORER PRO, phpSiteBackup) to versions that fix the g_pcltar_lib_dir input handling.
  • If patching is not immediately possible, remove or disable the vulnerable PclTar library files if they are not required.
  • Enforce PHP configuration hardening such as allow_url_include=Off and allow_url_fopen=Off to block remote file inclusion.
  • Deploy a web application firewall rule to block requests containing URL schemes or path traversal in the g_pcltar_lib_dir parameter.
  • Restrict outbound network access from web servers to limit the ability to fetch remote payloads.

Detection

  • Search web server access logs for requests to lib/pcltar.lib.php or pcltar.php with g_pcltar_lib_dir containing http://, https://, ftp://, or similar remote URL schemes.
  • Monitor for unexpected outbound HTTP connections from the web server to external hosts following such requests.
  • Use file integrity monitoring to detect new or modified PHP files in web-accessible directories that could be dropped payloads.
  • Review PHP error logs for include or require failures referencing remote URLs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://osvdb.org/34803
http://osvdb.org/36009
http://secunia.com/advisories/25230 Vendor Advisory
http://www.attrition.org/pipermail/vim/2007-May/001618.html
http://www.hackers.ir/advisories/joomla.html ExploitVendor Advisory
http://www.securityfocus.com/archive/1/466687/100/0/threaded
http://www.securityfocus.com/archive/1/478503/100/0/threaded
http://www.securityfocus.com/bid/23613
http://www.securityfocus.com/bid/23708
http://www.securityfocus.com/bid/24660
http://www.securityfocus.com/bid/25528
http://www.vupen.com/english/advisories/2007/1511 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/33837
https://exchange.xforce.ibmcloud.com/vulnerabilities/34273
https://exchange.xforce.ibmcloud.com/vulnerabilities/35092
https://www.exploit-db.com/exploits/3781
https://www.exploit-db.com/exploits/3915
https://www.exploit-db.com/exploits/4111
http://osvdb.org/34803
http://osvdb.org/36009
http://secunia.com/advisories/25230 Vendor Advisory
http://www.attrition.org/pipermail/vim/2007-May/001618.html
http://www.hackers.ir/advisories/joomla.html ExploitVendor Advisory
http://www.securityfocus.com/archive/1/466687/100/0/threaded
http://www.securityfocus.com/archive/1/478503/100/0/threaded
http://www.securityfocus.com/bid/23613
http://www.securityfocus.com/bid/23708
http://www.securityfocus.com/bid/24660
http://www.securityfocus.com/bid/25528
http://www.vupen.com/english/advisories/2007/1511 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/33837
https://exchange.xforce.ibmcloud.com/vulnerabilities/34273
https://exchange.xforce.ibmcloud.com/vulnerabilities/35092
https://www.exploit-db.com/exploits/3781
https://www.exploit-db.com/exploits/3915
https://www.exploit-db.com/exploits/4111

Track CVE-2007-2199 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-3225Joomla permissions and access controls vulnerabilityJoomla! before 1.5.4 allows attackers to access administration functionality, which has unknown impact and attack vectors related to a missing "LDAP …EPSS 1.5%10.0CVE-2006-1047Joomla vulnerabilityUnspecified vulnerability in the "Remember Me login functionality" in Joomla! 1.0.7 and earlier has unknown impact and attack vectors.EPSS 1.9%10.0CVE-2006-0303Joomla vulnerabilityMultiple unspecified vulnerabilities in the (1) publishing component, (2) Contact Component, (3) TinyMCE Compressor, and (4) other components in Joom…EPSS 1.4%10.0CVE-2005-3773Joomla vulnerabilityUnspecified vulnerability in Joomla! before 1.0.4 has unknown impact and attack vectors, related to "Potential misuse of Media component file managem…EPSS 1.7%7.8CVE-2006-1028Joomla vulnerabilityfeedcreator.class.php (aka the syndication component) in Joomla! 1.0.7 allows remote attackers to cause a denial of service (stressed file cache) by …EPSS 1.9%7.5CVE-2008-5671Joomla code injection vulnerabilityPHP remote file inclusion vulnerability in index.php in Joomla! 1.0.11 through 1.0.14, when RG_EMULATION is enabled in configuration.php, allows remo…EPSS 1.7%7.5CVE-2008-4102Joomla vulnerabilityJoomla! 1.5 before 1.5.7 initializes PHP's PRNG with a weak seed, which makes it easier for attackers to guess the pseudo-random values produced by P…EPSS 2.4%7.5CVE-2008-4105Joomla improper input validation vulnerabilityJRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remote attackers to conduct "varia…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2007-2199), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.