Description
Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allows remote attackers to upload and execute arbitrary PHP code via a filename with a double extension such as .php.jpg.
Remediation
References
Related Vulnerabilities
WordPress Plugin arcResBookingWidget Multiple Vulnerabilities (1.0)
WordPress Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2008-5113)
MODX Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2017-7321)
Drupal Core 9.4.x Cross-Site Scripting (9.4.0 - 9.4.2)
WordPress Plugin MyBookTable Bookstore by Author Media Cross-Site Scripting (3.2.1)