TROYANOSYVIRUS
Back to CVEs

CVE-2009-4819

N/A

Description

Multiple unrestricted file upload vulnerabilities in upload.php in PHPhotoalbum allow remote attackers to execute arbitrary code by uploading a file with a (1) .php.pgif or (2) .php.pjpeg double extension, then accessing it via a direct request to the file in albums/userpics/.

CVE Details

CVSS v3.1 ScoreN/A
Published4/27/2010
Last Modified4/29/2026
Sourcenvd
Honeypot Sightings0

Affected Products

stoverud:phphotoalbum

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.