7.5
CVSSv2

CVE-2005-4171

Published: 11/12/2005 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The "Upload new image" command in the "Manage Images" eFiction 1.1, when members are allowed to upload images, allows remote malicious users to execute arbitrary PHP code by uploading a filename with a .php extension that contains a GIF header, which passes the image validity check but executes any PHP code within the file.

Vulnerable Product Search on Vulmon Subscribe to Product

efiction project efiction 1.1

Exploits

<?php # ---efiction20_xplphp 1519 17/11/2005 # # # # eFiction <= 20 fake GIF Shell Upload # # coded by rgod # # ...