CVE-2007-5720
UnknownEPSS 1.96%
Last modified
CVE-2007-5720 is a vulnerability of currently unknown severity. Unrestricted file upload vulnerability in the profiles script in ProfileCMS 1.0 allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors involving creation of a profile.. EPSS estimates a 1.96% chance of exploitation in the next 30 days.
Description
Unrestricted file upload vulnerability in the profiles script in ProfileCMS 1.0 allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors involving creation of a profile.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Profilecms | Profilecms | 1.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-5720?
Unrestricted file upload vulnerability in the profiles script in ProfileCMS 1.0 allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors involving creation of a profile.
How severe is CVE-2007-5720?
Severity scoring for CVE-2007-5720 is pending analysis. The EPSS model estimates a 1.96% probability of exploitation in the next 30 days.
How do I fix CVE-2007-5720?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-5714The Gentoo ebuild of MLDonkey before 2.9.0-r3 has a p2p user…
- CVE-2007-5715DenyHosts 2.6 processes OpenSSH sshd "not listed in AllowUse…
- CVE-2007-5716Unspecified vulnerability in the Internet Protocol (IP) func…
- CVE-2007-5717Unspecified vulnerability in Sun Fire X2100 M2 and X2200 M2 …
- CVE-2007-5718vobcopy 0.5.14 allows local users to append data to an arbit…
- CVE-2007-5719SQL injection vulnerability in bb_func_search.php in miniBB …
- CVE-2007-5721PHP remote file inclusion vulnerability in _theme/breadcrumb…
- CVE-2007-5722Stack-based buffer overflow in a certain ActiveX control in …
- CVE-2007-5723Heap-based buffer overflow in the samp_send function in nuau…
- CVE-2007-5724Multiple cross-site scripting (XSS) vulnerabilities in Omnis…
- CVE-2007-5725Multiple cross-site scripting (XSS) vulnerabilities in Smart…
- CVE-2007-5726Unspecified vulnerability in the Stream Control Transmission…
Are you affected by CVE-2007-5720?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
