← Vulnerability feed

Vulnerability record · CVE-2007-5156 · published 1 October 2007

CVE-2007-5156: Cardinal cms project cardinal cms vulnerability

CCardinal Cms Project · Cardinal Cms

Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.beta, La-Nai CMS, Syntax CMS, Cardinal Cms, and probably other products, allows remote attackers to upload and execute arbitrary PHP code via a file whose name contains ".php." and has an unknown extension, which is recognized as a .php file by the Apache HTTP server, a different vulnerability than CVE-2006-0658 and CVE-2006-2529.

7.5 CVSS 2.0 High EPSS 8.0% · top 5.4%
7.5CVSS 2.0 base score
8.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
38References, 10 tagged exploit
16 Jun 2026Last modified by NVD

Description

Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.beta, La-Nai CMS, Syntax CMS, Cardinal Cms, and probably other products, allows remote attackers to upload and execute arbitrary PHP code via a file whose name contains ".php." and has an unknown extension, which is recognized as a .php file by the Apache HTTP server, a different vulnerability than CVE-2006-0658 and CVE-2006-2529.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://dev.fckeditor.net/changeset/973 Vendor Advisory
http://dev.fckeditor.net/ticket/1325 Vendor Advisory
http://downloads.securityfocus.com/vulnerabilities/exploits/30677.php Broken Link
http://secunia.com/advisories/27123 Third Party Advisory
http://secunia.com/advisories/27174 Third Party Advisory
http://securityreason.com/securityalert/3182 ExploitThird Party Advisory
http://sourceforge.net/forum/forum.php?forum_id=743930 Broken Link
http://sourceforge.net/project/shownotes.php?release_id=546000 Broken Link
http://www.securityfocus.com/archive/1/480830/100/0/threaded ExploitThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/29422 Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/30677 Third Party AdvisoryVDB Entry
http://www.vupen.com/english/advisories/2007/3464 Third Party Advisory
http://www.vupen.com/english/advisories/2007/3465 Third Party Advisory
http://www.waraxe.us/advisory-57.html ExploitThird Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/42425 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/42733 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/44455 Third Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/5618 ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/5688 ExploitThird Party AdvisoryVDB Entry
http://dev.fckeditor.net/changeset/973 Vendor Advisory
http://dev.fckeditor.net/ticket/1325 Vendor Advisory
http://downloads.securityfocus.com/vulnerabilities/exploits/30677.php Broken Link
http://secunia.com/advisories/27123 Third Party Advisory
http://secunia.com/advisories/27174 Third Party Advisory
http://securityreason.com/securityalert/3182 ExploitThird Party Advisory
http://sourceforge.net/forum/forum.php?forum_id=743930 Broken Link
http://sourceforge.net/project/shownotes.php?release_id=546000 Broken Link
http://www.securityfocus.com/archive/1/480830/100/0/threaded ExploitThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/29422 Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/30677 Third Party AdvisoryVDB Entry
http://www.vupen.com/english/advisories/2007/3464 Third Party Advisory
http://www.vupen.com/english/advisories/2007/3465 Third Party Advisory
http://www.waraxe.us/advisory-57.html ExploitThird Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/42425 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/42733 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/44455 Third Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/5618 ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/5688 ExploitThird Party AdvisoryVDB Entry

Track CVE-2007-5156 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2007-5156), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.