Lucene search

K
prionPRIOn knowledge basePRION:CVE-2007-5307
HistoryOct 09, 2007 - 6:17 p.m.

Command injection

2007-10-0918:17:00
PRIOn knowledge base
www.prio-n.com
10

7.4 High

AI Score

Confidence

Low

0.054 Low

EPSS

Percentile

93.2%

ELSEIF CMS Beta 0.6 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter’s hash value, which allows remote attackers to execute arbitrary PHP code by uploading a .php file via externe/swfupload/upload.php. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in ELSEIF CMS.

CPENameOperatorVersion
else_if_cmseq0.6.0-beta

7.4 High

AI Score

Confidence

Low

0.054 Low

EPSS

Percentile

93.2%