Vulnerability Database

296,202

Total vulnerabilities in the database

CVE-2007-1639

Unrestricted file upload vulnerability in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allows remote authenticated users to upload and execute arbitrary PHP code via a file with an executable extension, which is then accessed by the (1) calendar or (2) file management module, or possibly unspecified other files.

  • Published: Mar 24, 2007
  • Updated: Apr 13, 2023
  • CVE: CVE-2007-1639
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4.6
  • AV:N/AC:H/Au:S/C:P/I:P/A:P

No CWE or OWASP classifications available.