Remote File Upload Issues in Uber Uploader Versions Prior to 5.3.6
CVE-2007-6676

Currently unrated

Key Information:

Vendor
CVE Published:
8 January 2008

What is CVE-2007-6676?

The default configuration of Uber Uploader versions 5.3.6 and earlier fails to restrict uploads of potentially harmful file extensions such as .html and .asp. This flaw allows remote attackers to upload malicious files via key scripts like uu_file_upload.php and uber_uploader_file.php, which could compromise the integrity of the web application. Administrators must proactively manage file upload configurations to mitigate these risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.