Description
Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allows remote attackers to upload and execute arbitrary PHP code via a filename with a double extension such as .php.jpg.
Remediation
References
Related Vulnerabilities
WordPress Plugin Front-end Editor 'upload.php' Arbitrary File Upload (2.2.1)
WordPress Plugin MC4WP:Mailchimp for WordPress Cross-Site Scripting (4.0.10)
Magento XML Injection (aka Blind XPath Injection) Vulnerability (CVE-2021-21019)
MySQL CVE-2018-2758 Vulnerability (CVE-2018-2758)
Family Connections Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-0699)