PT-2007-7361 · Punbb · Punbb
Published
2007-12-27
·
Updated
2017-08-08
·
CVE-2007-6527
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
PunBB imgUpload module version 1.3.2
Description
The issue allows remote attackers to upload and execute arbitrary content by exploiting the insufficient verification of uploaded files in the imgUpload module. This is achieved by uploading a file with a MIME type of JPG, GIF, or PNG, which is not properly checked by the
uploadimg.php script.Recommendations
For PunBB imgUpload module version 1.3.2, consider disabling the
uploadimg.php script until a patch is available to properly verify the type of uploaded files, restricting the execution of arbitrary content.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Punbb