CVE-2007-4913: Code Injection
ipskernel/classupload.php in Invision Power Board (IPB or IP.Board) 2.3.1 up to 20070912 allows remote attackers to upload arbitrary script files with crafted image filenames to uploads/, where they are saved with a .txt extension and are not executable. NOTE: there are limited usage scenarios under which this would be a vulnerability, but it is being tracked by CVE since the vendor has stated it is security-relevant.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4913?
CVE-2007-4913 is considered a medium severity vulnerability due to its potential for arbitrary file upload.
How do I fix CVE-2007-4913?
To fix CVE-2007-4913, upgrade to a patched version of Invision Power Board that addresses this vulnerability.
What are the risks associated with CVE-2007-4913?
The risks associated with CVE-2007-4913 include the possibility of unauthorized execution of scripts if the security measures are bypassed.
Which versions of Invision Power Board are affected by CVE-2007-4913?
Versions of Invision Power Board up to 2.3.1 are affected by CVE-2007-4913.
Can CVE-2007-4913 allow for remote attacks?
Yes, CVE-2007-4913 allows remote attackers to upload arbitrary script files, posing a significant security threat.