CVE-2010-0996: Medium severity e107 e107 vulnerability
Unrestricted file upload vulnerability in e107 before 0.7.20 allows remote authenticated users to execute arbitrary code by uploading a .php.filetypesphp file. NOTE: the vendor disputes the significance of this issue, noting that "an odd set of preferences and a missing file" are required.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0996?
CVE-2010-0996 is considered a medium severity vulnerability due to the unauthorized ability to execute arbitrary code.
How do I fix CVE-2010-0996?
To fix CVE-2010-0996, upgrade to e107 version 0.7.20 or later, which addresses the unrestricted file upload issue.
What type of vulnerability is CVE-2010-0996?
CVE-2010-0996 is an unrestricted file upload vulnerability that allows for potentially malicious code execution.
Who is affected by CVE-2010-0996?
CVE-2010-0996 affects e107 CMS versions prior to 0.7.20, including various earlier releases.
What can an attacker do with CVE-2010-0996?
An attacker exploiting CVE-2010-0996 can upload a malicious .php file, potentially leading to remote code execution.