CVE-2007-6527 Information
Feb 14, 2021
cve
Description
uploadimg.php in the Automatic Image Upload with Thumbnails (imgUpload) module 1.3.2 for PunBB only verifies the Content-type field of uploaded files which allows remote attackers to upload and execute arbitrary content via a file with a (1) JPG (2) GIF or (3) PNG MIME type.
Reference
http://osvdb.org/42809 http://secunia.com/advisories/28138 http://www.fortconsult.net/images/pdf/advisories/punBB_imgUpload.pdf https://exchange.xforce.ibmcloud.com/vulnerabilities/39150
Share on: