PT-2008-4271 · Full Revolution · Full Revolution Aspwebcalendar 2008

Alemin_Krali

·

Publicado

2008-06-24

·

Atualizado

2017-09-29

·

CVE-2008-2832

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Full Revolution aspWebCalendar 2008
Description The issue concerns an unrestricted file upload vulnerability. This vulnerability allows remote attackers to upload and execute arbitrary code via the FILE1 parameter in an "uploadfileprocess" action, likely followed by a direct request to the file in "calendar/eventimages/".
Recommendations For Full Revolution aspWebCalendar 2008, restrict access to the "uploadfileprocess" action and the "calendar/eventimages/" directory to prevent arbitrary code execution. Consider implementing validation and restrictions on file uploads to mitigate the risk of exploitation.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-2832

Produtos afetados

Full Revolution Aspwebcalendar 2008