CVE-2009-4819
EUVD-2009-478227.04.2010, 15:30
Multiple unrestricted file upload vulnerabilities in upload.php in PHPhotoalbum allow remote attackers to execute arbitrary code by uploading a file with a (1) .php.pgif or (2) .php.pjpeg double extension, then accessing it via a direct request to the file in albums/userpics/.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| stoverud | phphotoalbum | 0.3 |
| stoverud | phphotoalbum | 0.4 |
| stoverud | phphotoalbum | 0.5 |
𝑥
= Vulnerable software versions