Vulnerability record · CVE-2007-3632 · published 10 July 2007
CVE-2007-3632: LimeSurvey PHP remote file inclusion in PEAR admin classes
Limesurvey · Limesurvey
LimeSurvey (PHPSurveyor) 1.49RC2 contains multiple PHP remote file inclusion flaws in bundled PEAR files under admin/classes/pear/, where the homedir parameter is used to include remote files. An attacker can point that parameter at a hostile URL and cause the server to execute arbitrary PHP code. The record names only version 1.49RC2, so other versions cannot be confirmed as affected from the supplied data.
Description
Multiple PHP remote file inclusion vulnerabilities in LimeSurvey (aka PHPSurveyor) 1.49RC2 allow remote attackers to execute arbitrary PHP code via a URL in the homedir parameter to (1) OLE/PPS/File.php, (2) OLE/PPS/Root.php, (3) Spreadsheet/Excel/Writer.php, or (4) OLE/PPS.php in admin/classes/pear/; or (5) Worksheet.php, (6) Parser.php, (7) Workbook.php, (8) Format.php, or (9) BIFFwriter.php in admin/classes/pear/Spreadsheet/Excel/Writer/.
AV:N/AC:M/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated code execution with public exploit code and very high EPSS, though the affected product is an old release and no KEV listing exists.
What it is
LimeSurvey (PHPSurveyor) 1.49RC2 contains multiple PHP remote file inclusion flaws in bundled PEAR files under admin/classes/pear/, where the homedir parameter is used to include remote files. An attacker can point that parameter at a hostile URL and cause the server to execute arbitrary PHP code. The record names only version 1.49RC2, so other versions cannot be confirmed as affected from the supplied data.
Impact
Successful exploitation gives the attacker arbitrary PHP code execution in the context of the web server, which can lead to full compromise of the LimeSurvey host and its data.
Attack surface
The flaw is reachable over the network via HTTP requests to the affected PEAR scripts in admin/classes/pear/, with the homedir parameter carrying the attacker-controlled URL. The CVSS vector shows no authentication required (Au:N) but medium access complexity (AC:M), and no user interaction is indicated.
Exploitation
CVE-2007-3632 is not listed in CISA KEV, but EPSS is high at 0.615 (99th percentile) and an Exploit-DB entry (4156) exists, indicating public exploit code is available.
What to do
- Upgrade LimeSurvey to a release later than 1.49RC2 that removes or fixes the vulnerable PEAR includes; confirm the fixed version with the vendor since the record does not state one.
- If upgrade is not immediately possible, remove or block direct web access to admin/classes/pear/ and the affected files (OLE/PPS/File.php, OLE/PPS/Root.php, OLE/PPS.php, Spreadsheet/Excel/Writer.php, Worksheet.php, Parser.php, Workbook.php, Format.php, BIFFwriter.php).
- Disable allow_url_include and allow_url_fopen in PHP so remote URLs cannot be included.
- Restrict access to the admin interface by IP or authentication at the web server layer.
- Review PHP error and access logs for requests containing homedir with http:// or https:// values.
Detection
- Search web access logs for requests to admin/classes/pear/ paths with homedir parameters containing external URLs.
- Alert on PHP include or require errors referencing remote hosts in application logs.
- Monitor for outbound HTTP connections from the web server to unfamiliar hosts that correlate with PEAR file requests.
- Use file integrity monitoring on the LimeSurvey webroot to catch newly written PHP files after suspicious requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-3632 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-3632), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.