CVE
- Id
- 24996
- CVE No.
- CVE-2007-1639
- Status
- Candidate
- Description
- Unrestricted file upload vulnerability in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allows remote authenticated users to upload and execute arbitrary PHP code via a file with an executable extension, which is then accessed by the (1) calendar or (2) file management module, or possibly unspecified other files.
- Phase
- Assigned (20070323)
- Votes
- None (candidate not yet proposed)
- Comments