Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-1866

Опубликовано: 17 апр. 2008
Источник: nvd
CVSS2: 9
EPSS Средний

Описание

admin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote authenticated users to upload arbitrary PHP scripts in a ZIP archive, which is written to templateZip/ and then automatically extracted under templates/ for execution via a direct request.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:pixel_motion:pixel_motion_blog:*:*:*:*:*:*:*:*

EPSS

Процентиль: 94%
0.15112
Средний

9 Critical

CVSS2

Дефекты

CWE-94

Связанные уязвимости

github
почти 4 года назад

admin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote authenticated users to upload arbitrary PHP scripts in a ZIP archive, which is written to templateZip/ and then automatically extracted under templates/ for execution via a direct request.

EPSS

Процентиль: 94%
0.15112
Средний

9 Critical

CVSS2

Дефекты

CWE-94