Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-4098

Опубликовано: 29 нояб. 2009
Источник: nvd
CVSS2: 6
EPSS Средний

Описание

Unrestricted file upload vulnerability in banner-edit.php in OpenX adserver 2.8.1 and earlier allows remote authenticated users with banner / file upload permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an images directory.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openx:openx:*:*:*:*:*:*:*:*
Версия до 2.8.1 (включая)
cpe:2.3:a:openx:openx:2.4:*:*:*:*:*:*:*
cpe:2.3:a:openx:openx:2.6.1:*:*:*:*:*:*:*
cpe:2.3:a:openx:openx:2.6.3:*:*:*:*:*:*:*
cpe:2.3:a:openx:openx:2.8:*:*:*:*:*:*:*

EPSS

Процентиль: 98%
0.50581
Средний

6 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

debian
около 16 лет назад

Unrestricted file upload vulnerability in banner-edit.php in OpenX ads ...

github
почти 4 года назад

Unrestricted file upload vulnerability in banner-edit.php in OpenX adserver 2.8.1 and earlier allows remote authenticated users with banner / file upload permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an images directory.

EPSS

Процентиль: 98%
0.50581
Средний

6 Medium

CVSS2

Дефекты

CWE-20