PT-2007-4700 · E107 · E107

Clorox

·

Publicado

2007-06-27

·

Atualizado

2017-10-11

·

CVE-2007-3429

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions e107 versions 0.7.8 and earlier
Description The issue concerns an unrestricted file upload vulnerability. When photograph upload is enabled, remote attackers can upload and execute arbitrary PHP code via a filename with a double extension, such as .php.jpg.
Recommendations For versions 0.7.8 and earlier, restrict or disable the photograph upload feature in signup.php to prevent exploitation until a fix is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-3429

Produtos afetados

E107