PT-2007-3523 · Maran · Maran Php Forum

Dj7Xpl

·

Publicado

2007-04-24

·

Atualizado

2017-10-11

·

CVE-2007-2182

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Maran PHP Forum (affected versions not specified)
Description The issue concerns an unrestricted file upload vulnerability. This allows remote attackers to upload and execute arbitrary PHP files. The vulnerability can be exploited by adding a trailing %00 in a filename in the page parameter of the forum write.php file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2182

Produtos afetados

Maran Php Forum