CVE-2007-0764
F3Site <2.1 - RCE
Title source: llmDescription
Unrestricted file upload vulnerability in F3Site 2.1 and earlier allows remote authenticated administrators to upload and execute arbitrary PHP scripts via GIF86 header in a file in the uplf parameter, which can be later accessed via a relative pathname in the dir parameter in adm.php.
Exploits (1)
Scores
EPSS
0.0538
EPSS Percentile
90.1%
Details
Status
published
Products (1)
f3site/f3site
2.1
Published
Feb 06, 2007
Tracked Since
Feb 18, 2026