Skip to main content

CVE-2007-3632

CVSS Score Not Available
70.47%
HIGH RiskEPSS (99th percentile)

Multiple PHP remote file inclusion vulnerabilities in LimeSurvey (aka PHPSurveyor) 1.49RC2 allow remote attackers to execute arbitrary PHP code via a URL in the homedir parameter to (1) OLE/PPS/File.php, (2) OLE/PPS/Root.php, (3) Spreadsheet/Excel/Writer.php, or (4) OLE/PPS.php in admin/classes/pear/; or (5) Worksheet.php, (6) Parser.php, (7) Workbook.php, (8) Format.php, or (9) BIFFwriter.php in admin/classes/pear/Spreadsheet/Excel/Writer/.

Published: 7/10/2007
Modified: 4/9/2025
Back to CVE Lookup

Vulnerability Summary

EPSS Score (Exploitation Probability)

70.47%HIGH Exploitation Risk
99th percentile

This vulnerability has a 70.47% probability of being exploited in the next 30 days, ranking higher than 99% of all scored CVEs.