PT-2007-4058 · W2Box · W2Box

Publicado

2007-05-17

·

Atualizado

2017-07-29

·

CVE-2007-2742

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions w2box version 4.0.0 Beta4
Description The issue allows remote attackers to upload arbitrary PHP code via a filename with a double extension, such as .php.jpg, enabling potential code execution on the server.
Recommendations For version 4.0.0 Beta4, consider restricting file uploads to only allow specific, verified extensions to prevent arbitrary PHP code execution. As a temporary workaround, restrict access to file upload functionality until a proper fix is applied.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2742

Produtos afetados

W2Box