Lucene search

K
cveFlexeraCVE-2010-1514
HistoryJun 15, 2010 - 2:30 p.m.

CVE-2010-1514

2010-06-1514:30:01
flexera
web.nvd.nist.gov
25
cve-2010-1514
security
vulnerability
tomatocms
unrestricted file upload
remote execution

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

7.5

Confidence

Low

EPSS

0.003

Percentile

70.5%

Unrestricted file upload vulnerability in TomatoCMS 2.0.6 and earlier allows remote authenticated users, with certain privileges, to execute arbitrary PHP code by uploading an image file, and then accessing it via a direct request to the file in an unspecified directory.

Affected configurations

Nvd
Node
tomatocmstomatocmsRange≀2.0.6
OR
tomatocmstomatocmsMatch2.0.0
OR
tomatocmstomatocmsMatch2.0.1
OR
tomatocmstomatocmsMatch2.0.2
OR
tomatocmstomatocmsMatch2.0.3
OR
tomatocmstomatocmsMatch2.0.3.1430
OR
tomatocmstomatocmsMatch2.0.3.1622
OR
tomatocmstomatocmsMatch2.0.4
OR
tomatocmstomatocmsMatch2.0.5
VendorProductVersionCPE
tomatocmstomatocms*cpe:2.3:a:tomatocms:tomatocms:*:*:*:*:*:*:*:*
tomatocmstomatocms2.0.0cpe:2.3:a:tomatocms:tomatocms:2.0.0:*:*:*:*:*:*:*
tomatocmstomatocms2.0.1cpe:2.3:a:tomatocms:tomatocms:2.0.1:*:*:*:*:*:*:*
tomatocmstomatocms2.0.2cpe:2.3:a:tomatocms:tomatocms:2.0.2:*:*:*:*:*:*:*
tomatocmstomatocms2.0.3cpe:2.3:a:tomatocms:tomatocms:2.0.3:*:*:*:*:*:*:*
tomatocmstomatocms2.0.3.1430cpe:2.3:a:tomatocms:tomatocms:2.0.3.1430:*:*:*:*:*:*:*
tomatocmstomatocms2.0.3.1622cpe:2.3:a:tomatocms:tomatocms:2.0.3.1622:*:*:*:*:*:*:*
tomatocmstomatocms2.0.4cpe:2.3:a:tomatocms:tomatocms:2.0.4:*:*:*:*:*:*:*
tomatocmstomatocms2.0.5cpe:2.3:a:tomatocms:tomatocms:2.0.5:*:*:*:*:*:*:*

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

7.5

Confidence

Low

EPSS

0.003

Percentile

70.5%

Related for CVE-2010-1514