6.8
CVE-2007-4026
- EPSS 1.17%
- Veröffentlicht 26.07.2007 19:30:00
- Zuletzt bearbeitet 16.06.2026 22:43:15
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
epesi framework before 0.8.6 does not properly verify file extensions, which allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors involving the gallery images upload feature. NOTE: some of these details are obtained from third party information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Telaxus Llc ≫ Epesi Version <= 0.8.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.17% | 0.632 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
http://osvdb.org/38600
http://secunia.com/advisories/26175
http://sourceforge.net/project/shownotes.php?release_id=527102
https://exchange.xforce.ibmcloud.com/vulnerabilities/35596