CVE

Id
25382  
CVE No.
CVE-2007-2025  
Status
Candidate  
Description
Unrestricted file upload vulnerability in the UpLoad feature (lib/plugin/UpLoad.php) in PhpWiki 1.3.11p1 allows remote attackers to upload arbitrary PHP files with a double extension, as demonstrated by .php.3, which is interpreted by Apache as being a valid PHP file.  
Phase
Assigned (20070413)  
Votes
None (candidate not yet proposed)  
Comments