AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2007-2025

HIGH · CVSS 7.5 EPSS 2.50%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2007-04-13 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2007-2025
Severity
HIGH
CVSS
7.5
EPSS
2.50%
Apache

Original NVD Description

Unrestricted file upload vulnerability in the UpLoad feature (lib/plugin/UpLoad.php) in PhpWiki 1.3.11p1 allows remote attackers to upload arbitrary PHP files with a double extension, as demonstrated by .php.3, which is interpreted by Apache as being a valid PHP file.