Lucene search

K
cve[email protected]CVE-2009-4412
HistoryDec 24, 2009 - 4:30 p.m.

CVE-2009-4412

2009-12-2416:30:00
web.nvd.nist.gov
31
vulnerability
file upload
serendipity
cve-2009-4412
code execution

6 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

7.3 High

AI Score

Confidence

Low

0.014 Low

EPSS

Percentile

86.5%

Unrestricted file upload vulnerability in Serendipity before 1.5 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the file in an unspecified directory. NOTE: some of these details are obtained from third party information.

Affected configurations

NVD
Node
s9yserendipityRange1.5beta1
OR
s9yserendipityMatch0.3
OR
s9yserendipityMatch0.4
OR
s9yserendipityMatch0.5
OR
s9yserendipityMatch0.5pl1
OR
s9yserendipityMatch0.6
OR
s9yserendipityMatch0.6pl3
OR
s9yserendipityMatch0.7
OR
s9yserendipityMatch0.7.1
OR
s9yserendipityMatch0.8
OR
s9yserendipityMatch0.8.1
OR
s9yserendipityMatch0.8.2
OR
s9yserendipityMatch0.8.3
OR
s9yserendipityMatch0.8.4
OR
s9yserendipityMatch0.8.5
OR
s9yserendipityMatch0.9
OR
s9yserendipityMatch0.9.1
OR
s9yserendipityMatch1.0
OR
s9yserendipityMatch1.0.1
OR
s9yserendipityMatch1.0.2
OR
s9yserendipityMatch1.0.3
OR
s9yserendipityMatch1.0.4
OR
s9yserendipityMatch1.1
OR
s9yserendipityMatch1.1beta1
OR
s9yserendipityMatch1.1.1
OR
s9yserendipityMatch1.1.2
OR
s9yserendipityMatch1.1.3
OR
s9yserendipityMatch1.1.4
OR
s9yserendipityMatch1.2
OR
s9yserendipityMatch1.2.1
OR
s9yserendipityMatch1.3
OR
s9yserendipityMatch1.3.1
OR
s9yserendipityMatch1.4
OR
s9yserendipityMatch1.4.1

6 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

7.3 High

AI Score

Confidence

Low

0.014 Low

EPSS

Percentile

86.5%

Related for CVE-2009-4412