Lucene search

K
cve[email protected]CVE-2008-2267
HistoryMay 16, 2008 - 12:54 p.m.

CVE-2008-2267

2008-05-1612:54:00
CWE-20
web.nvd.nist.gov
26
cve
incomplete blacklist vulnerability
javaupload.php
postlet
filemanager module
cms made simple

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.7 High

AI Score

Confidence

High

0.137 Low

EPSS

Percentile

95.7%

Incomplete blacklist vulnerability in javaUpload.php in Postlet in the FileManager module in CMS Made Simple 1.2.4 and earlier allows remote attackers to execute arbitrary code by uploading a file with a name ending in (1) .jsp, (2) .php3, (3) .cgi, (4) .dhtml, (5) .phtml, (6) .php5, or (7) .jar, then accessing it via a direct request to the file in modules/FileManager/postlet/.

Affected configurations

NVD
Node
cms_made_simplecms_made_simpleMatch1.2.4

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.7 High

AI Score

Confidence

High

0.137 Low

EPSS

Percentile

95.7%

Related for CVE-2008-2267