Lucene search

K
cveMitreCVE-2010-0390
HistoryJan 26, 2010 - 6:30 p.m.

CVE-2010-0390

2010-01-2618:30:01
mitre
web.nvd.nist.gov
30
cve-2010-0390
file upload vulnerability
php f1 max's image uploader
remote code execution
apache
pjpeg
jpeg extensions
nvd

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

8

Confidence

Low

EPSS

0.026

Percentile

90.3%

Unrestricted file upload vulnerability in maxImageUpload/index.php in PHP F1 Max’s Image Uploader 1.0, when Apache is not configured to handle the mime-type for files with pjpeg or jpeg extensions, allows remote attackers to execute arbitrary code by uploading a file with a pjpeg or jpeg extension, then accessing it via a direct request to the file in original/. NOTE: some of these details are obtained from third party information.

Affected configurations

Nvd
Node
phpf1max\'s_image_uploaderMatch1.0
VendorProductVersionCPE
phpf1max\'s_image_uploader1.0cpe:2.3:a:phpf1:max\'s_image_uploader:1.0:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

8

Confidence

Low

EPSS

0.026

Percentile

90.3%

Related for CVE-2010-0390