PT-2007-6705 · Profilecms · Profilecms

R00T

·

Published

2007-10-30

·

Updated

2017-09-29

·

CVE-2007-5720

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ProfileCMS version 1.0
Description The issue allows remote attackers to upload and execute arbitrary PHP code. This is achieved through unspecified vectors involving the creation of a profile in the profiles script.
Recommendations For ProfileCMS version 1.0, consider restricting or disabling the profiles script to prevent the upload and execution of arbitrary PHP code until a fix is available.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5720

Affected Products

Profilecms