Description
ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the upload parameter to images.php.
Exploits (1)
References (7)
Scores
EPSS
0.2187
EPSS Percentile
95.8%
Details
CWE
CWE-434
Status
published
Products (1)
e107/e107
< 0.617
Published
Dec 31, 2004
Tracked Since
Feb 18, 2026