Lucene search

K
cve[email protected]CVE-2007-1097
HistoryFeb 26, 2007 - 5:28 p.m.

CVE-2007-1097

2007-02-2617:28:00
CWE-20
web.nvd.nist.gov
40
cve-2007-1097
file upload vulnerability
wiclear
php code execution
nvd
security issue

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.016

Percentile

87.3%

Unrestricted file upload vulnerability in the onAttachFiles function in the upload tool (inc/lib/attachment.lib.php) in Wiclear before 0.11.1 allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors related to filename validation. NOTE: some details were obtained from third party information.

Affected configurations

NVD
Node
wiclearwiclearRange0.11
VendorProductVersionCPE
wiclearwiclearcpe:/a:wiclear:wiclear::::

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.016

Percentile

87.3%

Related for CVE-2007-1097