Description American Financing eMail Image Upload 4.1版本的output.php中存在不限制文件上传漏洞。远程攻击者可以借助未明向量,上传并执行任意代码。
References https://www.threatquarters.com/cves/CVE-2007-4499 https://www.secualive.jp/en/feed/jvn/vulnerability/detailinfo/JVNDB-2007-002548/ https://cve.imfht.com/detail/CVE-2007-4498 https://strobes.co/vi/cve/CVE-2007-4499 https://www.scaprepo.com/control.jsp?search=cve&command=search&startPage=33716
Related VulnerabilitiesPoCCVE-2026-5524: Divi Form Builder <=5.1.8 - Unauthenticated Arbitrary File Upload RCEPoCCVE-2026-32475: Elementor Pro <=4.2.1 - Unauthenticated Arbitrary File Upload via Form HandlerFileRise /uploads 文件读取漏洞(CVE-2026-25231)鎧應科技|CMS-WS/CMS-SE/SMP - Arbitrary File Upload網韻資訊|NewSiteServer (NSS)新式校園網站系統 - Arbitrary File UploadPoCCVE-2026-0558: LolLMS <= 2.2.0 - Unauthenticated File UploadPoCCVE-2026-20896: Gitea Docker Image <= 1.26.2 - Reverse Proxy Header Authentication BypassPoCCVE-2026-13001: Podlove Podcast Publisher <= 4.5.1 - Arbitrary File UploadPoCCVE-2026-57827: RSFiles! for Joomla - Arbitrary File UploadPoCmonitorr-file-upload: Monitorr Services Configuration - Arbitrary File Upload二一零零科技|公文管理系統 - Arbitrary File UploadPoCCVE-2024-56064: WP SuperBackup <= 2.3.3 - Unauthenticated Arbitrary File Upload to RCEPoCCVE-2026-14483: Realtyna Organic IDX/WPL <= 5.2.0 - Unauthenticated Arbitrary File Upload