PT-2007-1608 · Uber · Uber Uploader
Published
2007-01-09
·
Updated
2018-10-16
·
CVE-2007-0123
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Uber Uploader version 4.2
Description
The issue allows remote attackers to upload and execute arbitrary PHP scripts by naming them with a .phtml extension, which bypasses the .php extension check but is still executable on some server configurations.
Recommendations
For Uber Uploader version 4.2, consider restricting file uploads to only allow specific, necessary file types, and implement additional checks to prevent the execution of uploaded scripts, such as verifying the file extension and validating user input. As a temporary workaround, consider disabling the file upload feature until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Uber Uploader