Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2005-2699

Опубликовано: 26 авг. 2005
Источник: nvd
CVSS2: 4.6
EPSS Низкий

Описание

Unrestricted file upload vulnerability in admin/admin.php in PHPKit 1.6.1 allows remote authenticated administrators to execute arbitrary PHP code by uploading a .php file to the content/images/ directory using images.php. NOTE: if a PHPKit administrator must already have access to the end system to install or modify configuration of the product, then this issue might not cross privilege boundaries, and should not be included in CVE.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:phpkit:phpkit:1.6.1:*:*:*:*:*:*:*

EPSS

Процентиль: 36%
0.00151
Низкий

4.6 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Unrestricted file upload vulnerability in admin/admin.php in PHPKit 1.6.1 allows remote authenticated administrators to execute arbitrary PHP code by uploading a .php file to the content/images/ directory using images.php. NOTE: if a PHPKit administrator must already have access to the end system to install or modify configuration of the product, then this issue might not cross privilege boundaries, and should not be included in CVE.

EPSS

Процентиль: 36%
0.00151
Низкий

4.6 Medium

CVSS2

Дефекты

NVD-CWE-Other