Логотип exploitDog
bind:CVE-2007-6479
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2007-6479

Количество 2

Количество 2

nvd логотип

CVE-2007-6479

около 18 лет назад

Unrestricted file upload vulnerability in the "My productions" component for main/auth/profile.php (aka the "My profile" page) in Dokeos 1.8.4 allows remote authenticated users to upload and execute arbitrary PHP files via a filename with a double extension, which can then be accessed through a URI under main/upload/users/.

CVSS2: 4.9
EPSS: Низкий
github логотип

GHSA-232r-27pv-pm68

почти 4 года назад

Unrestricted file upload vulnerability in the "My productions" component for main/auth/profile.php (aka the "My profile" page) in Dokeos 1.8.4 allows remote authenticated users to upload and execute arbitrary PHP files via a filename with a double extension, which can then be accessed through a URI under main/upload/users/.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2007-6479

Unrestricted file upload vulnerability in the "My productions" component for main/auth/profile.php (aka the "My profile" page) in Dokeos 1.8.4 allows remote authenticated users to upload and execute arbitrary PHP files via a filename with a double extension, which can then be accessed through a URI under main/upload/users/.

CVSS2: 4.9
5%
Низкий
около 18 лет назад
github логотип
GHSA-232r-27pv-pm68

Unrestricted file upload vulnerability in the "My productions" component for main/auth/profile.php (aka the "My profile" page) in Dokeos 1.8.4 allows remote authenticated users to upload and execute arbitrary PHP files via a filename with a double extension, which can then be accessed through a URI under main/upload/users/.

5%
Низкий
почти 4 года назад

Уязвимостей на страницу