CVE-2007-5231: Input Validation
Unrestricted file upload vulnerability in admin/uploadfiles.php in Zomplog 3.8.1 and earlier allows remote authenticated administrators to upload and execute arbitrary .php files by sending a modified MIME type. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2007-5230.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5231?
CVE-2007-5231 has a high severity level due to the ability to upload and execute arbitrary PHP files.
How do I fix CVE-2007-5231?
To fix CVE-2007-5231, update to the latest version of Zomplog, ensuring you are beyond version 3.8.1.
Can CVE-2007-5231 be exploited by unauthenticated users?
Yes, CVE-2007-5231 can be exploited by unauthenticated attackers by leveraging the vulnerabilities of CVE-2007-5230.
What versions of Zomplog are affected by CVE-2007-5231?
CVE-2007-5231 affects Zomplog versions 3.8.1 and earlier, including versions 3.8 and 3.7.6.
What type of vulnerability is CVE-2007-5231?
CVE-2007-5231 is an unrestricted file upload vulnerability that allows for the execution of arbitrary PHP files.