PT-2007-4058 · W2Box · W2Box

Published

2007-05-17

·

Updated

2017-07-29

·

CVE-2007-2742

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions w2box version 4.0.0 Beta4
Description The issue allows remote attackers to upload arbitrary PHP code via a filename with a double extension, such as .php.jpg, enabling potential code execution on the server.
Recommendations For version 4.0.0 Beta4, consider restricting file uploads to only allow specific, verified extensions to prevent arbitrary PHP code execution. As a temporary workaround, restrict access to file upload functionality until a proper fix is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2742

Affected Products

W2Box