PT-2007-1957 · Unknown · Upload-Service

Ahmad Muammar W.K

+1

·

Published

2007-01-25

·

Updated

2018-10-16

·

CVE-2007-0497

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Upload-Service version 1.0
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the maindir parameter when register globals is enabled. This is a result of a PHP remote file inclusion vulnerability in the upload/top.php file.
Recommendations For Upload-Service version 1.0, consider disabling the register globals setting to prevent exploitation, and restrict access to the upload/top.php file until a patch is available. As a temporary workaround, avoid using the maindir parameter in the affected file until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0497

Affected Products

Upload-Service