PT-2007-7361 · Punbb · Punbb
Publicado
2007-12-27
·
Atualizado
2017-08-08
·
CVE-2007-6527
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
PunBB imgUpload module version 1.3.2
Description
The issue allows remote attackers to upload and execute arbitrary content by exploiting the insufficient verification of uploaded files in the imgUpload module. This is achieved by uploading a file with a MIME type of JPG, GIF, or PNG, which is not properly checked by the
uploadimg.php script.Recommendations
For PunBB imgUpload module version 1.3.2, consider disabling the
uploadimg.php script until a patch is available to properly verify the type of uploaded files, restricting the execution of arbitrary content.Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Punbb