Lucene search

K
cve[email protected]CVE-2007-4640
HistoryAug 31, 2007 - 11:17 p.m.

CVE-2007-4640

2007-08-3123:17:00
CWE-94
CWE-264
web.nvd.nist.gov
21
security
vulnerability
file upload
pakupaku cms
remote execution

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

7.5 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.3%

Unrestricted file upload vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to upload and execute arbitrary PHP files in uploads/ via an Uploads action.

Affected configurations

NVD
Node
pakupakupakupaku_cmsRange0.4

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

7.5 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.3%

Related for CVE-2007-4640