peter bassill · operator
$ cve CVE-2005-4171 JSON

CVE-2005-4171 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 7.9% (pctl 95)

Patch early

A public exploit exists.

Description

The "Upload new image" command in the "Manage Images" eFiction 1.1, when members are allowed to upload images, allows remote attackers to execute arbitrary PHP code by uploading a filename with a .php extension that contains a GIF header, which passes the image validity check but executes any PHP code within the file.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS7.9% — more likely to be exploited than 95% of all CVEs
On CISA KEVno
Public exploityes
Published2005-12-11
Last modified2026-06-16

Affected (1)

VendorProduct
efiction projectefiction

Public exploits

SourceTitleDate
exploit-dbeFiction 2.0 - Fake '.GIF' Arbitrary File Upload2005-11-25

References

→ the Explorer  ·  watch your stack  ·  NVD