CVE-2007-4026 Information
Feb 14, 2021
cve
Description
epesi framework before 0.8.6 does not properly verify file extensions which allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors involving the gallery images upload feature. NOTE: some of these details are obtained from third party information.
Reference
http://osvdb.org/38600 http://secunia.com/advisories/26175 http://sourceforge.net/project/shownotes.php?release_id=527102 https://exchange.xforce.ibmcloud.com/vulnerabilities/35596
Share on: