PT-2007-3020 · Phprojekt · Phprojekt
Published
2007-03-23
·
Updated
2018-10-16
·
CVE-2007-1639
CVSS v2.0
4.6
Medium
| Vector | AV:N/AC:H/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
PHProjekt version 5.2.0
Description:
The issue allows remote authenticated users to upload and execute arbitrary PHP code via a file with an executable extension. This can be accessed by the calendar or file management module. The vulnerability is exploitable when magic quotes gpc is disabled.
Recommendations:
For PHProjekt version 5.2.0, consider disabling file uploads or restricting executable file extensions as a temporary workaround until a patch is available. Restrict access to the calendar and file management modules to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phprojekt