Lucene search

K
cveMitreCVE-2008-6814
HistoryMay 28, 2009 - 2:30 p.m.

CVE-2008-6814

2009-05-2814:30:00
CWE-20
mitre
web.nvd.nist.gov
199
cve-2008-6814
unrestricted file upload
simpleboard
mambo
remote code execution
vulnerability
nvd

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.8

Confidence

Low

EPSS

0.129

Percentile

95.5%

Unrestricted file upload vulnerability in image_upload.php in the SimpleBoard (com_simpleboard) component 1.0.1 and earlier for Mambo allows remote attackers to execute arbitrary code by uploading a file with an executable extension and an image/jpeg content type, then accessing this file via a direct request to the file in components/com_simpleboard/, a different vulnerability than CVE-2006-3528.

Affected configurations

Nvd
Node
jan_de_graaffcom_simpleboardRange1.0.1
OR
jan_de_graaffcom_simpleboardMatch0.9
OR
jan_de_graaffcom_simpleboardMatch0.9.1
OR
jan_de_graaffcom_simpleboardMatch0.9.2
OR
jan_de_graaffcom_simpleboardMatch1.0rc1
OR
jan_de_graaffcom_simpleboardMatch1.0rc2
OR
jan_de_graaffcom_simpleboardMatch1.0rc3
AND
mambomambo
VendorProductVersionCPE
jan_de_graaffcom_simpleboard*cpe:2.3:a:jan_de_graaff:com_simpleboard:*:*:*:*:*:*:*:*
jan_de_graaffcom_simpleboard0.9cpe:2.3:a:jan_de_graaff:com_simpleboard:0.9:*:*:*:*:*:*:*
jan_de_graaffcom_simpleboard0.9.1cpe:2.3:a:jan_de_graaff:com_simpleboard:0.9.1:*:*:*:*:*:*:*
jan_de_graaffcom_simpleboard0.9.2cpe:2.3:a:jan_de_graaff:com_simpleboard:0.9.2:*:*:*:*:*:*:*
jan_de_graaffcom_simpleboard1.0cpe:2.3:a:jan_de_graaff:com_simpleboard:1.0:rc1:*:*:*:*:*:*
jan_de_graaffcom_simpleboard1.0cpe:2.3:a:jan_de_graaff:com_simpleboard:1.0:rc2:*:*:*:*:*:*
jan_de_graaffcom_simpleboard1.0cpe:2.3:a:jan_de_graaff:com_simpleboard:1.0:rc3:*:*:*:*:*:*
mambomambo*cpe:2.3:a:mambo:mambo:*:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.8

Confidence

Low

EPSS

0.129

Percentile

95.5%