CVE-2007-6676
Last modified
CVE-2007-6676 is a vulnerability of currently unknown severity. The default configuration of Uber Uploader (UU) 5.3.6 and earlier does not block uploads of (1) .html, (2) .asp, and other possibly dangerous extensions, which allows remote attackers to use these extensions in uploads via (a) uu_file_upload.php, related to uu_file_upload.js and (b) uber_uploader_file.php, related to uber_uploader_file.js, a different issue than CVE-2007-0123. NOTE: the vendor disputes the severity of the issue, noting that it is the administrator's responsibility to "add file extensions that you may or may not want uploaded.". EPSS estimates a 1.19% chance of exploitation in the next 30 days.
Description
The default configuration of Uber Uploader (UU) 5.3.6 and earlier does not block uploads of (1) .html, (2) .asp, and other possibly dangerous extensions, which allows remote attackers to use these extensions in uploads via (a) uu_file_upload.php, related to uu_file_upload.js and (b) uber_uploader_file.php, related to uber_uploader_file.js, a different issue than CVE-2007-0123. NOTE: the vendor disputes the severity of the issue, noting that it is the administrator's responsibility to "add file extensions that you may or may not want uploaded."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Uber Uploader | Uber Uploader | <= 5.3.6 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-6676?
How severe is CVE-2007-6676?
How do I fix CVE-2007-6676?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-6670SQL injection vulnerability in search.php in PHCDownload 1.1…
- CVE-2007-6671SQL injection vulnerability in login_form.asp in Instant Sof…
- CVE-2007-6672Mortbay Jetty 6.1.5 and 6.1.6 allows remote attackers to byp…
- CVE-2007-6673Cross-site scripting (XSS) vulnerability in Makale Scripti a…
- CVE-2007-6674Cross-site scripting (XSS) vulnerability in Default.asp in R…
- CVE-2007-6675The b_system_comments_show function in htdocs/modules/system…
- CVE-2007-6677Cross-site scripting (XSS) vulnerability in Peter's Random A…
- CVE-2007-6678Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2007-6679Unspecified vulnerability in the Administrative Console in I…
- CVE-2007-6680Trusted Execution in IBM AIX 6.1 uses an incorrect pathname …
- CVE-2007-6681Stack-based buffer overflow in modules/demux/subtitle.c in V…
- CVE-2007-6682Format string vulnerability in the httpd_FileCallBack functi…
Are you affected by CVE-2007-6676?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
