6.5
CVSSv2

CVE-2007-4057

Published: 30/07/2007 Updated: 29/09/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in pfs.php in Neocrome Seditio 121 and previous versions allows remote authenticated users to upload arbitrary PHP code via a filename ending with (1) .php.gif, (2) .php.jpg, or (3) .php.png.

Vulnerable Product Search on Vulmon Subscribe to Product

neocrome seditio

Exploits

# Seditio CMS Remote File Upload Vulnerability # ReSearcher : ADT # Script : Seditio and Ldu Cms # Version : All Versions # Script HomePage : neocromenet/ # Dork : "powered by seditio" or "powered by ldu" # Risk : Very High! # Usage : Firstly, you register the victim web site After, go to "pfsphp" and upload your evil script! # ...