CVE-2007-3632
LimeSurvey 1.49RC2 - Remote File Inclusion via homedir Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3632. PoCs published by Yakir Wizman.
AI-analyzed exploit summary This is a writeup detailing a Remote File Inclusion (RFI) vulnerability in LimeSurvey (PHPSurveyor) version 1.49RC2. It lists multiple files vulnerable to RFI via the 'homedir' parameter but does not include executable exploit code.
Description
Multiple PHP remote file inclusion vulnerabilities in LimeSurvey (aka PHPSurveyor) 1.49RC2 allow remote attackers to execute arbitrary PHP code via a URL in the homedir parameter to (1) OLE/PPS/File.php, (2) OLE/PPS/Root.php, (3) Spreadsheet/Excel/Writer.php, or (4) OLE/PPS.php in admin/classes/pear/; or (5) Worksheet.php, (6) Parser.php, (7) Workbook.php, (8) Format.php, or (9) BIFFwriter.php in admin/classes/pear/Spreadsheet/Excel/Writer/.
Exploits (1)
This is a writeup detailing a Remote File Inclusion (RFI) vulnerability in LimeSurvey (PHPSurveyor) version 1.49RC2. It lists multiple files vulnerable to RFI via the 'homedir' parameter but does not include executable exploit code.