Lucene search

K
cve[email protected]CVE-2008-6930
HistoryAug 11, 2009 - 9:00 p.m.

CVE-2008-6930

2009-08-1121:00:00
CWE-264
web.nvd.nist.gov
21
nvd
cve-2008-6930
phpstore real estate
file upload vulnerability
remote authenticated users
arbitrary code execution

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

7.5 High

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

81.8%

Unrestricted file upload vulnerability in PHPStore Real Estate allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a logo, then accessing it via a direct request to the file in realty/re_images/.

Affected configurations

NVD
Node
phpstorereal_estate

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

7.5 High

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

81.8%

Related for CVE-2008-6930