CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:S/C:P/I:P/A:P
AI Score
Confidence
Low
EPSS
Percentile
70.5%
Unrestricted file upload vulnerability in TomatoCMS 2.0.6 and earlier allows remote authenticated users, with certain privileges, to execute arbitrary PHP code by uploading an image file, and then accessing it via a direct request to the file in an unspecified directory.
Vendor | Product | Version | CPE |
---|---|---|---|
tomatocms | tomatocms | * | cpe:2.3:a:tomatocms:tomatocms:*:*:*:*:*:*:*:* |
tomatocms | tomatocms | 2.0.0 | cpe:2.3:a:tomatocms:tomatocms:2.0.0:*:*:*:*:*:*:* |
tomatocms | tomatocms | 2.0.1 | cpe:2.3:a:tomatocms:tomatocms:2.0.1:*:*:*:*:*:*:* |
tomatocms | tomatocms | 2.0.2 | cpe:2.3:a:tomatocms:tomatocms:2.0.2:*:*:*:*:*:*:* |
tomatocms | tomatocms | 2.0.3 | cpe:2.3:a:tomatocms:tomatocms:2.0.3:*:*:*:*:*:*:* |
tomatocms | tomatocms | 2.0.3.1430 | cpe:2.3:a:tomatocms:tomatocms:2.0.3.1430:*:*:*:*:*:*:* |
tomatocms | tomatocms | 2.0.3.1622 | cpe:2.3:a:tomatocms:tomatocms:2.0.3.1622:*:*:*:*:*:*:* |
tomatocms | tomatocms | 2.0.4 | cpe:2.3:a:tomatocms:tomatocms:2.0.4:*:*:*:*:*:*:* |
tomatocms | tomatocms | 2.0.5 | cpe:2.3:a:tomatocms:tomatocms:2.0.5:*:*:*:*:*:*:* |