CVE-2007-3429 Information
Feb 14, 2021
cve
Description
Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier when photograph upload is enabled allows remote attackers to upload and execute arbitrary PHP code via a filename with a double extension such as .php.jpg.
Reference
http://osvdb.org/45426 http://www.g00ns-forum.net/showthread.php?t=9388 http://www.securityfocus.com/bid/24609 https://exchange.xforce.ibmcloud.com/vulnerabilities/35022 https://www.exploit-db.com/exploits/4099
Share on: