PT-2007-4700 · E107 · E107
Clorox
·
Published
2007-06-27
·
Updated
2017-10-11
·
CVE-2007-3429
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
e107 versions 0.7.8 and earlier
Description
The issue concerns an unrestricted file upload vulnerability. When photograph upload is enabled, remote attackers can upload and execute arbitrary PHP code via a filename with a double extension, such as
.php.jpg.Recommendations
For versions 0.7.8 and earlier, restrict or disable the photograph upload feature in
signup.php to prevent exploitation until a fix is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
E107