Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-1495

Опубликовано: 25 мар. 2008
Источник: nvd
CVSS2: 6.5
EPSS Низкий

Описание

Unrestricted file upload vulnerability in administrer/produits.php in PEEL, possibly 3.x and earlier, allows remote authenticated administrators to upload and execute arbitrary PHP files via a modified content type in an ajout action, as demonstrated by (1) image/gif and (2) application/pdf.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:peel:peel:1.0b:*:*:*:*:*:*:*
cpe:2.3:a:peel:peel:2.6:*:*:*:*:*:*:*
cpe:2.3:a:peel:peel:2.7:*:*:*:*:*:*:*

EPSS

Процентиль: 87%
0.03302
Низкий

6.5 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

github
больше 3 лет назад

Unrestricted file upload vulnerability in administrer/produits.php in PEEL, possibly 3.x and earlier, allows remote authenticated administrators to upload and execute arbitrary PHP files via a modified content type in an ajout action, as demonstrated by (1) image/gif and (2) application/pdf.

EPSS

Процентиль: 87%
0.03302
Низкий

6.5 Medium

CVSS2

Дефекты

CWE-20