7.5
CVSSv2

CVE-2007-5071

Published: 24/09/2007 Updated: 15/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Incomplete blacklist vulnerability in upload_img_cgi.php in Simple PHP Blog prior to 0.5.1 allows remote malicious users to upload dangerous files and execute arbitrary code, as demonstrated by a filename ending in .php. or a .htaccess file, a different vector than CVE-2005-2733. NOTE: the vulnerability was also present in a 0.5.1 download available in the early morning of 20070923. NOTE: the original 20070920 disclosure provided an incorrect filename, img_upload_cgi.php.

Vulnerable Product Search on Vulmon Subscribe to Product

alexander palmo simple php blog