MEDIUM · 4.6

CVE-2007-1639

Unrestricted file upload vulnerability in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allows remote authenticated users to upload and execute arbitrary PHP code via a file with an executable e...

Vulnerability Description

Unrestricted file upload vulnerability in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allows remote authenticated users to upload and execute arbitrary PHP code via a file with an executable extension, which is then accessed by the (1) calendar or (2) file management module, or possibly unspecified other files.

CVSS Score

4.6

MEDIUM

AV:N/AC:H/Au:S/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
PhpprojektPhpprojekt5.2.0

References

FAQ

What is CVE-2007-1639?

CVE-2007-1639 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Unrestricted file upload vulnerability in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allows remote authenticated users to upload and execute arbitrary PHP code via a file with an executable e...

How severe is CVE-2007-1639?

CVE-2007-1639 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-1639?

Check the references section above for vendor advisories and patch information. Affected products include: Phpprojekt Phpprojekt.