CVE-2007-3429
Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allow
Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allows remote attackers to upload and execute arbitrary PHP code via a filename with a double extension such as .php.jpg.
MEDIUM · CVSS 6.8
EPSS 0.04775
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0