CVE-2007-1604
Last modified
CVE-2007-1604 is a vulnerability of currently unknown severity. Multiple unrestricted file upload vulnerabilities in w-Agora (Web-Agora) allow remote attackers to upload and execute arbitrary PHP code (1) via a forum message with an attached file, which is stored under forums/hello/hello/notes/ or (2) by using browse_avatar.php to upload a file with a double extension, as demonstrated by .php.jpg.. EPSS estimates a 3.00% chance of exploitation in the next 30 days.
Description
Multiple unrestricted file upload vulnerabilities in w-Agora (Web-Agora) allow remote attackers to upload and execute arbitrary PHP code (1) via a forum message with an attached file, which is stored under forums/hello/hello/notes/ or (2) by using browse_avatar.php to upload a file with a double extension, as demonstrated by .php.jpg.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| W-Agora | W-Agora | 4.2.1 |
References
- http://secunia.com/advisories/24605Vendor Advisory
- http://secunia.com/advisories/24605Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-1604?
How severe is CVE-2007-1604?
How do I fix CVE-2007-1604?
Are you affected by CVE-2007-1604?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
