Unrestricted File Upload in Uber Uploader 4.2 by Uber
CVE-2007-0123

Currently unrated

Key Information:

Vendor
CVE Published:
9 January 2007

What is CVE-2007-0123?

The Uber Uploader 4.2 has a vulnerability that allows remote attackers to upload arbitrary PHP scripts by exploiting the file naming convention. Specifically, attackers can bypass the security measures of the .php extension check by using a .phtml extension. This misconfiguration may lead to unauthorized execution of the uploaded scripts on server environments wherein the .phtml files are treated as executable PHP scripts, posing a significant security threat.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.