ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the upload parameter to images.php.
Threat-Mapped Scoring
Score: 1.8
Priority: P4 - Informational (Low)
S9 – Sabotage of System/App
EPSS
Score: 0.21867 Percentile:
0.95493
CVSS Scoring
CVSS v2 Score: 7.5
Severity:
Mapped CWE(s)
CWE-434
: Unrestricted Upload of File with Dangerous Type
All CAPEC(s)
CAPEC-1: Accessing Functionality Not Properly Constrained by ACLs
CAPEC(s) with Mapped TTPs
CAPEC-1: Accessing Functionality Not Properly Constrained by ACLs
Mapped TTPs: