Lucene search

K
nvd[email protected]NVD:CVE-2009-4140
HistoryDec 22, 2009 - 10:30 p.m.

CVE-2009-4140

2009-12-2222:30:00
web.nvd.nist.gov
3

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

Low

EPSS

0.973

Percentile

99.9%

Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer, as used in Piwik 0.2.35 through 0.4.3, Woopra Analytics Plugin before 1.4.3.2, and possibly other products, when register_globals is enabled, allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension through the name parameter with the code in the HTTP_RAW_POST_DATA parameter, then accessing it via a direct request to the file in tmp-upload-images/.

Affected configurations

Nvd
Node
teethgrinder.co.ukopen_flash_chartMatch2.0beta_1
OR
teethgrinder.co.ukopen_flash_chartMatch2.0gamera
OR
teethgrinder.co.ukopen_flash_chartMatch2.0hyperion
OR
teethgrinder.co.ukopen_flash_chartMatch2.0ichor
OR
teethgrinder.co.ukopen_flash_chartMatch2.0j_rmungandr
OR
teethgrinder.co.ukopen_flash_chartMatch2.0j_rmungandr-2
OR
teethgrinder.co.ukopen_flash_chartMatch2.0kvasir
OR
teethgrinder.co.ukopen_flash_chartMatch2.0lug_wyrm_charmer
AND
matomomatomoMatch0.2.37
OR
matomomatomoMatch0.4.2
OR
matomomatomoMatch0.4.3
VendorProductVersionCPE
teethgrinder.co.ukopen_flash_chart2.0cpe:2.3:a:teethgrinder.co.uk:open_flash_chart:2.0:beta_1:*:*:*:*:*:*
teethgrinder.co.ukopen_flash_chart2.0cpe:2.3:a:teethgrinder.co.uk:open_flash_chart:2.0:gamera:*:*:*:*:*:*
teethgrinder.co.ukopen_flash_chart2.0cpe:2.3:a:teethgrinder.co.uk:open_flash_chart:2.0:hyperion:*:*:*:*:*:*
teethgrinder.co.ukopen_flash_chart2.0cpe:2.3:a:teethgrinder.co.uk:open_flash_chart:2.0:ichor:*:*:*:*:*:*
teethgrinder.co.ukopen_flash_chart2.0cpe:2.3:a:teethgrinder.co.uk:open_flash_chart:2.0:j_rmungandr:*:*:*:*:*:*
teethgrinder.co.ukopen_flash_chart2.0cpe:2.3:a:teethgrinder.co.uk:open_flash_chart:2.0:j_rmungandr-2:*:*:*:*:*:*
teethgrinder.co.ukopen_flash_chart2.0cpe:2.3:a:teethgrinder.co.uk:open_flash_chart:2.0:kvasir:*:*:*:*:*:*
teethgrinder.co.ukopen_flash_chart2.0cpe:2.3:a:teethgrinder.co.uk:open_flash_chart:2.0:lug_wyrm_charmer:*:*:*:*:*:*
matomomatomo0.2.37cpe:2.3:a:matomo:matomo:0.2.37:*:*:*:*:*:*:*
matomomatomo0.4.2cpe:2.3:a:matomo:matomo:0.4.2:*:*:*:*:*:*:*
Rows per page:
1-10 of 111

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

Low

EPSS

0.973

Percentile

99.9%