Back
CVE-2005-4423
Unrestricted file upload vulnerability in PHPFM before 0.2.3 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension to an accessible directory, as demonstrated using a file with a .php extension, aka "upload phpshell."
Published: Dec 20, 2005
Modified: Jun 16, 2026
CVSS Metrics
GitHub Security Advisory GHSA-9vjq-3gv6-2pf3
Unrestricted file upload vulnerability in PHPFM before 0.2.3 allows remote authenticated users to...
Risk Scores
CVSS Score
6.5 / 10
EPSS Score
2.87%
Top 14% most likely to be exploited
Threat Score
26.9 / 100
Data Sources
NVD
EPSS
GitHub