|
E107 Signup.PHP Arbitrary File Upload Vulnerability
e107 is prone to an arbitrary-file-upload vulnerability because the application fails to sufficiently sanitize user-supplied input. An attacker can exploit this vulnerability to upload PHP script code and execute it in the context of the webserver process. This issue affects e107 0.7.8; prior versions may also be vulnerable. NOTE: Reports indicate that this may not be an issue if the '/e107_admin/filetypes_.php' script is properly configured. By default, this script does not allow 'PHP' files to be uploaded. |
|
|
Privacy Statement |