Required CVE Record Information
Description
Incomplete blacklist vulnerability in upload_img_cgi.php in Simple PHP Blog before 0.5.1 allows remote attackers to upload dangerous files and execute arbitrary code, as demonstrated by a filename ending in .php. or a .htaccess file, a different vector than CVE-2005-2733. NOTE: the vulnerability was also present in a 0.5.1 download available in the early morning of 20070923. NOTE: the original 20070920 disclosure provided an incorrect filename, img_upload_cgi.php.
References 8 Total
- secunia.com: 26968 third-party-advisory
- securityfocus.com: 25747 vdb-entry
- exchange.xforce.ibmcloud.com: simplephpblog-uploadimgcgi-file-upload(36785) vdb-entry
- http://www.securenetwork.it/ricerca/advisory/download/SN-2007-03.txt
- http://www.simplephpblog.com/comments.php?y=07&m=09&entry=entry070923-004446
- http://www.simplephpblog.com/index.php?m=09&y=07
- securityfocus.com: 20070925 Simple PHP Blog Multiple Vulnerabilities mailing-list
- securityfocus.com: 20070920 SimplePHPBlog Hacking mailing-list
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 8 Total
- secunia.com: 26968 third-party-advisoryx_transferred
- securityfocus.com: 25747 vdb-entryx_transferred
- exchange.xforce.ibmcloud.com: simplephpblog-uploadimgcgi-file-upload(36785) vdb-entryx_transferred
- http://www.securenetwork.it/ricerca/advisory/download/SN-2007-03.txt x_transferred
- http://www.simplephpblog.com/comments.php?y=07&m=09&entry=entry070923-004446 x_transferred
- http://www.simplephpblog.com/index.php?m=09&y=07 x_transferred
- securityfocus.com: 20070925 Simple PHP Blog Multiple Vulnerabilities mailing-listx_transferred
- securityfocus.com: 20070920 SimplePHPBlog Hacking mailing-listx_transferred