6.8
CVSSv2

CVE-2007-3429

Published: 27/06/2007 Updated: 11/10/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and previous versions, when photograph upload is enabled, allows remote malicious users to upload and execute arbitrary PHP code via a filename with a double extension such as .php.jpg.

Vulnerable Product Search on Vulmon Subscribe to Product

e107 e107 0.7.6

e107 e107 0.7.7

e107 e107 0.7

e107 e107 0.7.1

e107 e107 0.7.8

e107 e107 0.7.4

e107 e107 0.7.5

e107 e107 0.7.2

e107 e107 0.7.3

Exploits

############################################################################################### # ___ ___ _ # / _ \ / _ \ | | # __ _| | | | | | |_ __ ___ _ __ ___| |_ # / _` | | | | | | | '_ \/ __| | '_ \ / _ \ __| # | (_| | |_| | |_| | | | \__ \_| | | | __/ |_ # \__, |\___/ \ ...