Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2007-2025

Опубликовано: 13 апр. 2007
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5

Описание

Unrestricted file upload vulnerability in the UpLoad feature (lib/plugin/UpLoad.php) in PhpWiki 1.3.11p1 allows remote attackers to upload arbitrary PHP files with a double extension, as demonstrated by .php.3, which is interpreted by Apache as being a valid PHP file.

РелизСтатусПримечание
dapper

ignored

end of life
devel

released

1.3.12p3-6.1
edgy

ignored

end of life, was needed
feisty

ignored

end of life, was needed
gutsy

released

1.3.12p3-6.1
hardy

released

1.3.12p3-6.1
intrepid

released

1.3.12p3-6.1
jaunty

released

1.3.12p3-6.1
karmic

released

1.3.12p3-6.1
upstream

needs-triage

Показывать по

Ссылки на источники

EPSS

Процентиль: 79%
0.01289
Низкий

7.5 High

CVSS2

Связанные уязвимости

nvd
больше 18 лет назад

Unrestricted file upload vulnerability in the UpLoad feature (lib/plugin/UpLoad.php) in PhpWiki 1.3.11p1 allows remote attackers to upload arbitrary PHP files with a double extension, as demonstrated by .php.3, which is interpreted by Apache as being a valid PHP file.

debian
больше 18 лет назад

Unrestricted file upload vulnerability in the UpLoad feature (lib/plug ...

github
больше 3 лет назад

Unrestricted file upload vulnerability in the UpLoad feature (lib/plugin/UpLoad.php) in PhpWiki 1.3.11p1 allows remote attackers to upload arbitrary PHP files with a double extension, as demonstrated by .php.3, which is interpreted by Apache as being a valid PHP file.

EPSS

Процентиль: 79%
0.01289
Низкий

7.5 High

CVSS2