I
mageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the upload parameter to images.php.
References
Configurations
History
20 Nov 2024, 23:52
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://e107.org/comment.php?comment.news.672 - Broken Link, Patch | |
| References | () http://secunia.com/advisories/13657 - Broken Link, Vendor Advisory | |
| References | () http://securitytracker.com/id?1012657 - Broken Link, Exploit, Third Party Advisory, VDB Entry | |
| References | () http://www.osvdb.org/12586 - Broken Link | |
| References | () http://www.securityfocus.com/bid/12111 - Broken Link, Third Party Advisory, VDB Entry | |
| References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/18670 - Third Party Advisory, VDB Entry | |
| References | () https://www.exploit-db.com/exploits/704 - Third Party Advisory, VDB Entry |
Information
Published : 2004-12-31 05:00
Updated : 2025-04-03 01:03
NVD link : CVE-2004-2262
Mitre link : CVE-2004-2262
CVE.ORG link : CVE-2004-2262
JSON object : View
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type