Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-3932

Опубликовано: 21 июл. 2007
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

uploadimg.php in the Expose RC35 and earlier (com_expose) component for Joomla! sends an error message but does not exit when it detects an attempt to upload a non-JPEG file, which allows remote attackers to upload and execute arbitrary PHP code in the img/ folder.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:joomla:expose:*:*:*:*:*:*:*:*
Версия до rc35 (включая)

EPSS

Процентиль: 89%
0.04469
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

uploadimg.php in the Expose RC35 and earlier (com_expose) component for Joomla! sends an error message but does not exit when it detects an attempt to upload a non-JPEG file, which allows remote attackers to upload and execute arbitrary PHP code in the img/ folder.

EPSS

Процентиль: 89%
0.04469
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other