← Vulnerability feed

Vulnerability record · CVE-2007-3632 · published 10 July 2007

CVE-2007-3632: LimeSurvey PHP remote file inclusion in PEAR admin classes

Limesurvey · Limesurvey

LimeSurvey (PHPSurveyor) 1.49RC2 contains multiple PHP remote file inclusion flaws in bundled PEAR files under admin/classes/pear/, where the homedir parameter is used to include remote files. An attacker can point that parameter at a hostile URL and cause the server to execute arbitrary PHP code. The record names only version 1.49RC2, so other versions cannot be confirmed as affected from the supplied data.

6.8 CVSS 2.0 Medium EPSS 62% · top 0.9%
6.8CVSS 2.0 base score
62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
24References
16 Jun 2026Last modified by NVD

Description

Multiple PHP remote file inclusion vulnerabilities in LimeSurvey (aka PHPSurveyor) 1.49RC2 allow remote attackers to execute arbitrary PHP code via a URL in the homedir parameter to (1) OLE/PPS/File.php, (2) OLE/PPS/Root.php, (3) Spreadsheet/Excel/Writer.php, or (4) OLE/PPS.php in admin/classes/pear/; or (5) Worksheet.php, (6) Parser.php, (7) Workbook.php, (8) Format.php, or (9) BIFFwriter.php in admin/classes/pear/Spreadsheet/Excel/Writer/.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote, unauthenticated code execution with public exploit code and very high EPSS, though the affected product is an old release and no KEV listing exists.

What it is

LimeSurvey (PHPSurveyor) 1.49RC2 contains multiple PHP remote file inclusion flaws in bundled PEAR files under admin/classes/pear/, where the homedir parameter is used to include remote files. An attacker can point that parameter at a hostile URL and cause the server to execute arbitrary PHP code. The record names only version 1.49RC2, so other versions cannot be confirmed as affected from the supplied data.

Impact

Successful exploitation gives the attacker arbitrary PHP code execution in the context of the web server, which can lead to full compromise of the LimeSurvey host and its data.

Attack surface

The flaw is reachable over the network via HTTP requests to the affected PEAR scripts in admin/classes/pear/, with the homedir parameter carrying the attacker-controlled URL. The CVSS vector shows no authentication required (Au:N) but medium access complexity (AC:M), and no user interaction is indicated.

Exploitation

CVE-2007-3632 is not listed in CISA KEV, but EPSS is high at 0.615 (99th percentile) and an Exploit-DB entry (4156) exists, indicating public exploit code is available.

What to do

  • Upgrade LimeSurvey to a release later than 1.49RC2 that removes or fixes the vulnerable PEAR includes; confirm the fixed version with the vendor since the record does not state one.
  • If upgrade is not immediately possible, remove or block direct web access to admin/classes/pear/ and the affected files (OLE/PPS/File.php, OLE/PPS/Root.php, OLE/PPS.php, Spreadsheet/Excel/Writer.php, Worksheet.php, Parser.php, Workbook.php, Format.php, BIFFwriter.php).
  • Disable allow_url_include and allow_url_fopen in PHP so remote URLs cannot be included.
  • Restrict access to the admin interface by IP or authentication at the web server layer.
  • Review PHP error and access logs for requests containing homedir with http:// or https:// values.

Detection

  • Search web access logs for requests to admin/classes/pear/ paths with homedir parameters containing external URLs.
  • Alert on PHP include or require errors referencing remote hosts in application logs.
  • Monitor for outbound HTTP connections from the web server to unfamiliar hosts that correlate with PEAR file requests.
  • Use file integrity monitoring on the LimeSurvey webroot to catch newly written PHP files after suspicious requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-3632 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-56422Limesurvey deserialization of untrusted data vulnerabilityA deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the server.EPSS 0.85%9.8CVE-2022-48008Limesurvey unrestricted file upload vulnerabilityAn arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file.EPSS 1.3%9.8CVE-2019-25019Limesurvey sql injection vulnerabilityLimeSurvey before 4.0.0-RC4 allows SQL injection via the participant model.EPSS 1.3%9.8CVE-2020-11455LimeSurvey file manager path traversalLimeSurvey before 4.1.12+200324 contains a path traversal flaw in application/controllers/admin/LimeSurveyFileManager.php. An unauthenticated remote …EPSS 97%analysed9.8CVE-2019-16184Limesurvey csv injection vulnerabilityA CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands via their survey responses th…EPSS 1.7%9.8CVE-2019-9960Limesurvey path traversal vulnerabilityThe downloadZip function in application/controllers/admin/export.php in LimeSurvey through 3.16.1+190225 allows a relative path.EPSS 13%9.8CVE-2018-17057Tecnick tcpdf deserialization of untrusted data vulnerabilityAn issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.EPSS 26%9.3CVE-2025-41375Limesurvey sql injection vulnerabilitySQL Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability allows an attacker to retrieve, create, update and delete database via '…EPSS 0.63%

Source: NIST National Vulnerability Database (record CVE-2007-3632), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.