Vulnerabilities > CVE-2007-3429 - Unspecified vulnerability in E107
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allows remote attackers to upload and execute arbitrary PHP code via a filename with a double extension such as .php.jpg.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 9 |
Exploit-Db
description | e107. CVE-2007-3429. Webapps exploit for php platform |
file | exploits/php/webapps/4099.txt |
id | EDB-ID:4099 |
last seen | 2016-01-31 |
modified | 2007-06-24 |
platform | php |
port | |
published | 2007-06-24 |
reporter | g00ns |
source | https://www.exploit-db.com/download/4099/ |
title | e107 <= 0.7.8 - photograph Arbitrary File Upload Vulnerability |
type | webapps |