CVE-2004-2262
CVE-2004-2262 is a high-severity vulnerability in E107 with a CVSS 2.0 base score of 7.5. Its EPSS exploit-prediction score of 15% places it in the 96th percentile, indicating an elevated likelihood of exploitation. The underlying weakness is classified as CWE-434.
Key facts
- Severity: High (CVSS 2.0 base score 7.5)
- EPSS exploit prediction: 15% (96th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-434
- Affected product: E107
- Published:
- Last modified:
Description
ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the upload parameter to images.php.
Frequently asked questions
- What is CVE-2004-2262?
- ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the upload parameter to images.php.
- How severe is CVE-2004-2262?
- CVE-2004-2262 has a CVSS 2.0 base score of 7.5, rated high severity.
- Is CVE-2004-2262 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 15% (96th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2004-2262?
- CVE-2004-2262 affects E107. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2004-2262?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2004-2262 published?
- CVE-2004-2262 was published on 2004-12-31 and last updated on 2026-06-16.
References
- http://e107.org/comment.php?comment.news.672
- http://secunia.com/advisories/13657
- http://securitytracker.com/id?1012657
- http://www.osvdb.org/12586
- http://www.securityfocus.com/bid/12111
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18670
- https://www.exploit-db.com/exploits/704
Affected products (1)
- cpe:2.3:a:e107:e107:*:*:*:*:*:*:*:*
More vulnerabilities in E107
- CVE-2008-1989 — Critical (CVSS 10.0): PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when…
- CVE-2022-50905 — Critical (CVSS 9.8): e107 CMS version 3.2.1 contains multiple vulnerabilities that allow cross-site scripting (XSS) attacks. The first…
- CVE-2021-27885 — High (CVSS 8.8): usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.
- CVE-2016-10753 — High (CVSS 8.8): e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without…
- CVE-2018-15901 — High (CVSS 8.8): e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including…
- CVE-2011-1513 — High (CVSS 7.5): Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the…
Other CWE-434 (Unrestricted Upload of File with Dangerous Type) vulnerabilities
- CVE-2026-75949 — Critical (CVSS 10.0): Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 -…
- CVE-2026-74803 — Critical (CVSS 10.0): Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts…
- CVE-2026-66665 — Critical (CVSS 10.0): Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
- CVE-2026-61900 — Critical (CVSS 10.0): Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla…
- CVE-2026-61424 — Critical (CVSS 10.0): Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla…
- CVE-2026-57719 — Critical (CVSS 10.0): Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using…
Browse all CWE-434 (Unrestricted Upload of File with Dangerous Type) vulnerabilities →