VulnerabilityModified
CVE-2004-2262
ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the upload parameter to images.php.
HIGH 7.5EPSS 14.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.9%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the upload parameter to images.php.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 14.91% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- e107/e107
- Source
- cve@mitre.org
References
- http://e107.org/comment.php?comment.news.672Broken Link, Patch
- http://secunia.com/advisories/13657Broken Link, Vendor Advisory
- http://securitytracker.com/id?1012657Broken Link, Exploit, Third Party Advisory, VDB Entry
- http://www.osvdb.org/12586Broken Link
- http://www.securityfocus.com/bid/12111Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18670Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/704Third Party Advisory, VDB Entry
- http://e107.org/comment.php?comment.news.672Broken Link, Patch
- http://secunia.com/advisories/13657Broken Link, Vendor Advisory
- http://securitytracker.com/id?1012657Broken Link, Exploit, Third Party Advisory, VDB Entry
- http://www.osvdb.org/12586Broken Link
- http://www.securityfocus.com/bid/12111Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18670Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/704Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.