CVE-2007-3429: Medium severity e107 e107 vulnerability
Published Jun 27, 2007
·Updated
Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allows remote attackers to upload and execute arbitrary PHP code via a filename with a double extension such as .php.jpg.
Affected Software
9 affected components
e107 e107=0.7.7
e107 e107=0.7.4
e107 e107=0.7.5
e107 e107=0.7.2
e107 e107=0.7
e107 e107=0.7.1
e107 e107=0.7.8
e107 e107=0.7.6
e107 e107=0.7.3
Event History
Jun 27, 2007
CVE Published
12:30 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3429?
CVE-2007-3429 is considered a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2007-3429?
To fix CVE-2007-3429, upgrade to e107 version 0.7.9 or later, which addresses this file upload vulnerability.
3
What systems are affected by CVE-2007-3429?
CVE-2007-3429 affects e107 versions 0.7.0 up to and including 0.7.8.
4
Can CVE-2007-3429 be exploited?
Yes, CVE-2007-3429 can be exploited by attackers to upload and execute arbitrary PHP code through manipulated file uploads.
5
What type of attack does CVE-2007-3429 enable?
CVE-2007-3429 enables arbitrary code execution attacks through unrestricted file uploads.