Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-1639

Опубликовано: 23 мар. 2007
Источник: nvd
CVSS2: 4.6
EPSS Низкий

Описание

Unrestricted file upload vulnerability in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allows remote authenticated users to upload and execute arbitrary PHP code via a file with an executable extension, which is then accessed by the (1) calendar or (2) file management module, or possibly unspecified other files.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:phpprojekt:phpprojekt:5.2.0:*:*:*:*:*:*:*

EPSS

Процентиль: 83%
0.01959
Низкий

4.6 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Unrestricted file upload vulnerability in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allows remote authenticated users to upload and execute arbitrary PHP code via a file with an executable extension, which is then accessed by the (1) calendar or (2) file management module, or possibly unspecified other files.

EPSS

Процентиль: 83%
0.01959
Низкий

4.6 Medium

CVSS2

Дефекты

NVD-CWE-Other