Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

E107 Signup.PHP Arbitrary File Upload Vulnerability

e107 is prone to an arbitrary-file-upload vulnerability because the application fails to sufficiently sanitize user-supplied input.

An attacker can exploit this vulnerability to upload PHP script code and execute it in the context of the webserver process.

This issue affects e107 0.7.8; prior versions may also be vulnerable.

NOTE: Reports indicate that this may not be an issue if the '/e107_admin/filetypes_.php' script is properly configured. By default, this script does not allow 'PHP' files to be uploaded.







 

Privacy Statement
Copyright 2009, SecurityFocus