VYPR
Unrated severityNVD Advisory· Published Mar 23, 2007· Updated Jun 16, 2026

CVE-2007-1639

CVE-2007-1639

Description

Unrestricted file upload vulnerability in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allows remote authenticated users to upload and execute arbitrary PHP code via a file with an executable extension, which is then accessed by the (1) calendar or (2) file management module, or possibly unspecified other files.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • cpe:2.3:a:phpprojekt:phpprojekt:5.2.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:phpprojekt:phpprojekt:5.2.0:*:*:*:*:*:*:*
    • (no CPE)range: =5.2.0

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.