Unrated severityNVD Advisory· Published Mar 23, 2007· Updated Apr 23, 2026
CVE-2007-1639
CVE-2007-1639
Description
Unrestricted file upload vulnerability in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allows remote authenticated users to upload and execute arbitrary PHP code via a file with an executable extension, which is then accessed by the (1) calendar or (2) file management module, or possibly unspecified other files.
Affected products
1- cpe:2.3:a:phpprojekt:phpprojekt:5.2.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- secunia.com/advisories/24509nvdPatchVendor Advisory
- www.securityfocus.com/bid/22956nvdPatch
- osvdb.org/35163nvd
- secunia.com/advisories/25748nvd
- security.gentoo.org/glsa/glsa-200706-07.xmlnvd
- securityreason.com/securityalert/2476nvd
- www.nruns.de/security_advisory_phprojekt_privilege_escalation.phpnvd
- www.phprojekt.com/index.phpnvd
- www.securityfocus.com/archive/1/462785/100/100/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/32995nvd
News mentions
0No linked articles in our index yet.