Unrestricted file upload vulnerability in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allows remote authenticated users to upload and execute arbitrary PHP code via a file with an executable extension, which is then accessed by the (1) calendar or (2) file management module, or possibly unspecified other files.
2007-03-23T23:19:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 4.6 (MEDIUM)
AV:N/AC:H/Au:S/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | phpprojekt | phpprojekt | 5.2.0 | Yes |