CVE-2007-1235

Unrestricted file upload vulnerability in sitex allows remote attackers to upload arbitrary PHP code via an avatar filename with a double extension such as .php.jpg, which fails verification and is saved as a .php file.
Configurations

Configuration 1

cpe:2.3:a:bj_sintay:sitex:0.7.3:*:*:*:*:*:*:*

Information

Published : 2007-03-03 07:19

Updated : 2018-10-16 04:37


NVD link : CVE-2007-1235

Mitre link : CVE-2007-1235

Products Affected
No products.
CWE