Neocrome · Neocrome Seditio · CVE-2007-4057
Name of the Vulnerable Software and Affected Versions:
Neocrome Seditio versions 121 and earlier
Description:
The issue concerns an unrestricted file upload vulnerability. This allows remote authenticated users to upload arbitrary PHP code via a filename ending with `.php.gif`, `.php.jpg`, or `.php.png`.
Recommendations:
For Neocrome Seditio versions 121 and earlier, consider restricting file uploads to only allow specific, safe file extensions to prevent the upload of malicious PHP code. As a temporary workaround, restrict access to the `pfs.php` file until a patch is available.