PT-2007-3368 · Phpwiki · Phpwiki

Reini Urban

·

Publicado

2007-04-13

·

Atualizado

2018-10-16

·

CVE-2007-2024

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PhpWiki versions 1.3.x
Description The issue concerns an unrestricted file upload vulnerability in the UpLoad feature, specifically in the lib/plugin/UpLoad.php file. This allows remote attackers to upload arbitrary PHP files with various extensions, including php3, php4, or php5.
Recommendations For PhpWiki versions 1.3.x, restrict access to the UpLoad feature in lib/plugin/UpLoad.php to prevent arbitrary file uploads until a patch is available. Consider temporarily disabling the UpLoad feature as a mitigation measure to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2024
DSA-1371-1

Produtos afetados

Phpwiki