PT-2007-3523 · Maran · Maran Php Forum

Dj7Xpl

·

Published

2007-04-24

·

Updated

2017-10-11

·

CVE-2007-2182

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Maran PHP Forum (affected versions not specified)
Description The issue concerns an unrestricted file upload vulnerability. This allows remote attackers to upload and execute arbitrary PHP files. The vulnerability can be exploited by adding a trailing %00 in a filename in the page parameter of the forum write.php file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2182

Affected Products

Maran Php Forum