PT-2007-4700 · E107 · E107
Clorox
·
Publicado
2007-06-27
·
Atualizado
2017-10-11
·
CVE-2007-3429
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
e107 versions 0.7.8 and earlier
Description
The issue concerns an unrestricted file upload vulnerability. When photograph upload is enabled, remote attackers can upload and execute arbitrary PHP code via a filename with a double extension, such as
.php.jpg.Recommendations
For versions 0.7.8 and earlier, restrict or disable the photograph upload feature in
signup.php to prevent exploitation until a fix is available.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
E107