e107.org
http://e107.org/comment.php?comment.news.672 CVE-2004-2262
e107 - 'include()' Remote File Upload
Record summary
CVE-2004-2262 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the upload parameter to images.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBe107 - 'include()' Remote File UploadExploitDB exploitby sysbugNot analyzed1 file
References
813657Third-party advisory
http://secunia.com/advisories/13657 1012657vdb entry
http://securitytracker.com/id?1012657 12586vdb entry
http://www.osvdb.org/12586 12111vdb entry
http://www.securityfocus.com/bid/12111 e107-images-file-upload(18670)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/18670 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-2262 704exploit
https://www.exploit-db.com/exploits/704