Vulnerabilities > CVE-2007-3429 - Unspecified vulnerability in E107
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN e107
exploit available
Summary
Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allows remote attackers to upload and execute arbitrary PHP code via a filename with a double extension such as .php.jpg.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 9 |
Exploit-Db
description | e107. CVE-2007-3429. Webapps exploit for php platform |
file | exploits/php/webapps/4099.txt |
id | EDB-ID:4099 |
last seen | 2016-01-31 |
modified | 2007-06-24 |
platform | php |
port | |
published | 2007-06-24 |
reporter | g00ns |
source | https://www.exploit-db.com/download/4099/ |
title | e107 <= 0.7.8 - photograph Arbitrary File Upload Vulnerability |
type | webapps |
References
- http://osvdb.org/45426
- http://osvdb.org/45426
- http://www.g00ns-forum.net/showthread.php?t=9388
- http://www.g00ns-forum.net/showthread.php?t=9388
- http://www.securityfocus.com/bid/24609
- http://www.securityfocus.com/bid/24609
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35022
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35022
- https://www.exploit-db.com/exploits/4099
- https://www.exploit-db.com/exploits/4099