Unrestricted File Upload in Uber Uploader 4.2 by Uber
CVE-2007-0123
Currently unrated
What is CVE-2007-0123?
The Uber Uploader 4.2 has a vulnerability that allows remote attackers to upload arbitrary PHP scripts by exploiting the file naming convention. Specifically, attackers can bypass the security measures of the .php extension check by using a .phtml extension. This misconfiguration may lead to unauthorized execution of the uploaded scripts on server environments wherein the .phtml files are treated as executable PHP scripts, posing a significant security threat.
