Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-4509

Опубликовано: 09 окт. 2008
Источник: nvd
CVSS2: 10
EPSS Средний

Описание

Unrestricted file upload vulnerability in processFiles.php in FOSS Gallery Admin and FOSS Gallery Public 1.0 beta allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the root directory.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:foss_gallery:foss_gallery:1.0:beta:admin:*:*:*:*:*
cpe:2.3:a:foss_gallery:foss_gallery:1.0:beta:public:*:*:*:*:*

EPSS

Процентиль: 94%
0.14001
Средний

10 Critical

CVSS2

Дефекты

CWE-20

Связанные уязвимости

github
почти 4 года назад

Unrestricted file upload vulnerability in processFiles.php in FOSS Gallery Admin and FOSS Gallery Public 1.0 beta allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the root directory.

EPSS

Процентиль: 94%
0.14001
Средний

10 Critical

CVSS2

Дефекты

CWE-20