7.5
CVSSv2

CVE-2007-5156

Published: 01/10/2007 Updated: 14/10/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.beta, La-Nai CMS, Syntax CMS, Cardinal Cms, and probably other products, allows remote malicious users to upload and execute arbitrary PHP code via a file whose name contains ".php." and has an unknown extension, which is recognized as a .php file by the Apache HTTP server, a different vulnerability than CVE-2006-0658 and CVE-2006-2529.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cardinal cms project cardinal cms 1.2

redlinesoft lanai cms

sitex cms project sitex cms 0.7.3

syntax cms project syntax cms

Vendor Advisories

Debian Bug report logs - #444928 CVE-2007-5156 remote php file inclusion vulnerability in fckeditor Package: knowledgeroot; Maintainer for knowledgeroot is (unknown); Reported by: Nico Golde <nion@debianorg> Date: Mon, 1 Oct 2007 22:39:01 UTC Severity: grave Tags: patch, security Fixed in versions knowledgeroot/0984- ...

Exploits

<?php /* -------------------------------------------------------------- La-Nai CMS <= 1216 (fckeditor) Arbitrary File Upload Exploit -------------------------------------------------------------- author: EgiX mail: n0b0d13s[at]gmail[dot]com link: sourceforgenet/projects/la-nai/ [-] vulnerable code in /inclu ...
<?php /* -------------------------------------------------------------- Syntax CMS <= 13 (fckeditor) Arbitrary File Upload Exploit -------------------------------------------------------------- Gr33ts t0 : EgiX, ThE GeNeRal L0s3r , Houssamix ,Str0ke <==> special THanks to EgiX For the Exploit Code author: Stack mail: ...