CyberSec.Space Logo
Back to CVE Browser

CVE-2007-1255

MEDIUM
6.0
CVSS Severity Score
EPSS Score0.1750%
EPSS Percentile1.99th
PublishedMar 3, 2007
Last ModifiedApr 23, 2026

Vulnerability Description

Unrestricted file upload vulnerability in admin.bbcode.php in Connectix Boards 0.7 and earlier allows remote authenticated administrators to execute arbitrary PHP code by uploading a crafted GIF smiley image with a .php extension via the uploadimage parameter to admin.php, which can be later accessed via a direct request for the file in smileys/. NOTE: this can be leveraged with a separate SQL injection issue for remote unauthenticated attacks.

Affected Platforms (CPE)

πŸ“¦
Connectix

Connectix Boards

= 0.4
πŸ“¦
Connectix

Connectix Boards

= 0.4.1
πŸ“¦
Connectix

Connectix Boards

= 0.4.2
πŸ“¦
Connectix

Connectix Boards

= 0.4.3
πŸ“¦
Connectix

Connectix Boards

= 0.4.4
πŸ“¦
Connectix

Connectix Boards

= 0.5
πŸ“¦
Connectix

Connectix Boards

= 0.5.1
πŸ“¦
Connectix

Connectix Boards

= 0.5.2
πŸ“¦
Connectix

Connectix Boards

= 0.5.3
πŸ“¦
Connectix

Connectix Boards

= 0.5.4
πŸ“¦
Connectix

Connectix Boards

= 0.5.5
πŸ“¦
Connectix

Connectix Boards

= 0.6
πŸ“¦
Connectix

Connectix Boards

= 0.6.1
πŸ“¦
Connectix

Connectix Boards

= 0.7

References & Advisories

Related Vulnerabilities