PT-2007-4700 · E107 · E107

Clorox

·

Published

2007-06-27

·

Updated

2017-10-11

·

CVE-2007-3429

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions e107 versions 0.7.8 and earlier
Description The issue concerns an unrestricted file upload vulnerability. When photograph upload is enabled, remote attackers can upload and execute arbitrary PHP code via a filename with a double extension, such as .php.jpg.
Recommendations For versions 0.7.8 and earlier, restrict or disable the photograph upload feature in signup.php to prevent exploitation until a fix is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3429

Affected Products

E107