Description
ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the upload parameter to images.php.
Remediation
References
Related Vulnerabilities
XWiki Incorrect Use of Privileged APIs Vulnerability (CVE-2022-24821)
WordPress Plugin WP-Forum Multiple SQL Injection Vulnerabilities (1.7.8)
WordPress Plugin Like Dislike Counter SQL Injection (1.2.3)
WordPress Plugin Zedna Contact form Arbitrary File Upload (1.0)
GeoServer Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-51444)