CVE-2007-3429
e107 <= 0.7.8 - Unauthenticated Arbitrary File Upload via Double Extension Bypass
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3429. PoCs published by g00ns.
AI-analyzed exploit summary This is a writeup describing an arbitrary file upload vulnerability in e107 <= 0.7.8. The vulnerability allows attackers to upload malicious PHP files by exploiting improper file extension validation in signup.php.
Description
Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allows remote attackers to upload and execute arbitrary PHP code via a filename with a double extension such as .php.jpg.
Exploits (1)
This is a writeup describing an arbitrary file upload vulnerability in e107 <= 0.7.8. The vulnerability allows attackers to upload malicious PHP files by exploiting improper file extension validation in signup.php.