Lucene search

K
cve[email protected]CVE-2008-3592
HistoryAug 11, 2008 - 11:41 p.m.

CVE-2008-3592

2008-08-1123:41:00
CWE-94
web.nvd.nist.gov
28
cve-2008-3592
file manager
remote code execution
security vulnerability
twentyone degrees symphony

8.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

7.7 High

AI Score

Confidence

High

0.01 Low

EPSS

Percentile

83.9%

Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension to a directory specified in the destination parameter, then accessing the uploaded file via a direct request, as demonstrated using workspace/masters/.

Affected configurations

NVD
Node
21degreessymphonyRange1.7.01
OR
21degreessymphonyMatch1.1
OR
21degreessymphonyMatch1.5
OR
21degreessymphonyMatch1.5.05
OR
21degreessymphonyMatch1.5.06
OR
21degreessymphonyMatch1.6.02
OR
21degreessymphonyMatch1.7

8.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

7.7 High

AI Score

Confidence

High

0.01 Low

EPSS

Percentile

83.9%

Related for CVE-2008-3592