PT-2008-3721 · Unknown · Project-Based Calendaring System
Gold_M
·
Publicado
2008-05-14
·
Atualizado
2017-09-29
·
CVE-2008-2216
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Project-Based Calendaring System (PBCS) version 0.7.1
Description:
The issue concerns an unrestricted file upload vulnerability. This vulnerability is located in the src/yopy upload.php file and allows remote authenticated users to upload arbitrary files to the tmp/uploads directory.
Recommendations:
For version 0.7.1, restrict access to the src/yopy upload.php file to prevent unauthorized file uploads until a patch is available. Consider implementing validation and restrictions on uploaded files to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Project-Based Calendaring System