CVE Database
/

CVE-2007-6527

Back to search

CVE-2007-6527

Published: Dec 27, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

uploadimg.php in the Automatic Image Upload with Thumbnails (imgUpload) module 1.3.2 for PunBB only verifies the Content-type field of uploaded files, which allows remote attackers to upload and execute arbitrary content via a file with a (1) JPG, (2) GIF, or (3) PNG MIME type.

VendorProductVersions

n/a

n/a

affected
n/a

References

28138
third-party-advisory
x_refsource_SECUNIA
punbb-uploadimg-file-upload(39150)
vdb-entry
x_refsource_XF
42809
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now