CVE-2005-4171

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/12/2005
Last modified:
03/04/2025

Description

The "Upload new image" command in the "Manage Images" eFiction 1.1, when members are allowed to upload images, allows remote attackers to execute arbitrary PHP code by uploading a filename with a .php extension that contains a GIF header, which passes the image validity check but executes any PHP code within the file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:efiction_project:efiction:1.1:*:*:*:*:*:*:*