CVE-2005-4171
The "Upload new image" command in the "Manage Images" eFiction 1.1, when members are allowed to upload images, allows remote attackers to execute arbitrary PHP code by uploading a filename with a .php extension that contains a GIF header, which passes…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (7.90%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The "Upload new image" command in the "Manage Images" eFiction 1.1, when members are allowed to upload images, allows remote attackers to execute arbitrary PHP code by uploading a filename with a .php extension that contains a GIF header, which passes the image validity check but executes any PHP code within the file.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 7.90% probability · 94th percentile
- CISA KEV
- Not listed
- Affected
- efiction project/efiction
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2005-11/0301.htmlExploit, Vendor Advisory
- http://rgod.altervista.org/efiction2_xpl.htmlExploit, Vendor Advisory
- http://secunia.com/advisories/17777Exploit, Vendor Advisory
- http://securitytracker.com/id?1015273Exploit
- http://www.efiction.wallflowergirl.com/forums/viewtopic.php?t=1555
- http://www.osvdb.org/21124
- http://www.securityfocus.com/bid/15568Exploit
- http://archives.neohapsis.com/archives/bugtraq/2005-11/0301.htmlExploit, Vendor Advisory
- http://rgod.altervista.org/efiction2_xpl.htmlExploit, Vendor Advisory
- http://secunia.com/advisories/17777Exploit, Vendor Advisory
- http://securitytracker.com/id?1015273Exploit
- http://www.efiction.wallflowergirl.com/forums/viewtopic.php?t=1555
- http://www.osvdb.org/21124
- http://www.securityfocus.com/bid/15568Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.