PublicDate: 2007-10-01 05:17:00 UTC Candidate: CVE-2007-5156 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5156 Description: Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.beta, La-Nai CMS, Syntax CMS, Cardinal Cms, and probably other products, allows remote attackers to upload and execute arbitrary PHP code via a file whose name contains ".php." and has an unknown extension, which is recognized as a .php file by the Apache HTTP server, a different vulnerability than CVE-2006-0658 and CVE-2006-2529. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: dapper_knowledgeroot: DNE edgy_knowledgeroot: DNE feisty_knowledgeroot: needed (reached end-of-life) gutsy_knowledgeroot: released (0.9.8.4-1.1) hardy_knowledgeroot: released (0.9.8.4-1.1) devel_knowledgeroot: released (0.9.8.4-1.1) upstream_knowledgeroot: needs-triage