CVE-2007-1552

Unrestricted file upload vulnerability in usercp.php in MetaForum 0.513 Beta restricts file types based on the MIME type in the Content-type HTTP header, which allows remote attackers to upload and execute arbitrary scripts via an image MIME type with a filename containing an executable extension such as .php.
Configurations

Configuration 1

cpe:2.3:a:metaforum:metaforum:0.513_beta:*:*:*:*:*:*:*

Information

Published : 2007-03-20 10:19

Updated : 2018-10-16 04:39


NVD link : CVE-2007-1552

Mitre link : CVE-2007-1552

Products Affected
No products.
CWE
CWE-637

Unnecessary Complexity in Protection Mechanism (Not Using 'Economy of Mechanism')