Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-1659

Опубликовано: 18 мая 2009
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

Unrestricted file upload vulnerability in admin/uploadimage.php in eLitius 1.0 allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files via an avatar file with an accepted Content-Type such as image/gif, then requesting the file in admin/banners/.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:intelliants:elitius:1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 79%
0.01233
Низкий

6.8 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Unrestricted file upload vulnerability in admin/uploadimage.php in eLitius 1.0 allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files via an avatar file with an accepted Content-Type such as image/gif, then requesting the file in admin/banners/.

EPSS

Процентиль: 79%
0.01233
Низкий

6.8 Medium

CVSS2

Дефекты

NVD-CWE-Other