Unrestricted file upload vulnerability in F3Site 2.1 and earlier allows remote authenticated administrators to upload and execute arbitrary PHP scripts via GIF86 header in a file in the uplf parameter, which can be later accessed via a relative pathname in the dir parameter in adm.php.
References
Configurations
Information
Published : 2007-02-05 18:28
Updated : 2017-10-18 18:30
NVD link : CVE-2007-0764
Mitre link : CVE-2007-0764
JSON object : View
CWE
Products Affected
f3site
- f3site


