Lucene search

K
cve[email protected]CVE-2007-0370
HistoryJan 19, 2007 - 11:28 p.m.

CVE-2007-0370

2007-01-1923:28:00
web.nvd.nist.gov
19
cve-2007-0370
phpbp
file upload vulnerability
remote code execution
sql injection

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.7 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

70.8%

Unrestricted file upload vulnerability in index.php in phpBP RC3 (2.204) and earlier allows remote administrators to inject arbitrary PHP code into an upload/banners/ file via a banners add operation that uploads the PHP code through an image_form parameter specifying a multiple-extension filename such as .jpg.vil.gif.php, which is stored in upload/banners/ under a different name, and executable via a direct request. NOTE: a separate SQL injection issue could be leveraged to make this vulnerability reachable by remote unauthenticated attackers.

Affected configurations

NVD
Node
phpbpphpbpMatchrc3_2.204
CPENameOperatorVersion
phpbp:phpbpphpbpeqrc3_2.204

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.7 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

70.8%

Related for CVE-2007-0370