Vulnerabilities > CVE-2007-3429 - Unspecified vulnerability in E107

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
e107
exploit available

Summary

Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allows remote attackers to upload and execute arbitrary PHP code via a filename with a double extension such as .php.jpg.

Exploit-Db

descriptione107. CVE-2007-3429. Webapps exploit for php platform
fileexploits/php/webapps/4099.txt
idEDB-ID:4099
last seen2016-01-31
modified2007-06-24
platformphp
port
published2007-06-24
reporterg00ns
sourcehttps://www.exploit-db.com/download/4099/
titlee107 <= 0.7.8 - photograph Arbitrary File Upload Vulnerability
typewebapps