"evaluatorComment":"Per: http://cwe.mitre.org/data/definitions/434.html\r\n\r\n'CWE-434: Unrestricted Upload of File with Dangerous Type'",
"descriptions":[
{
"lang":"en",
"value":"Multiple unrestricted file upload vulnerabilities in upload.php in PHPhotoalbum allow remote attackers to execute arbitrary code by uploading a file with a (1) .php.pgif or (2) .php.pjpeg double extension, then accessing it via a direct request to the file in albums/userpics/."
},
{
"lang":"es",
"value":"M\u00faltiples vulnerabilidades de subida de archivos sin restricci\u00f3n en upload.php en PHPhotoalbum permite a atacantes remotos ejecutar c\u00f3digo de su elecci\u00f3n subiendo un archivo con una extensi\u00f3n doble (1) .php.pgif o (2) .php.pjpeg, y accediendo a \u00e9l a trav\u00e9s de una petici\u00f3n directa al fichero en albums/userpics/."