PT-2008-4271 · Full Revolution · Full Revolution Aspwebcalendar 2008
Alemin_Krali
·
Publicado
2008-06-24
·
Atualizado
2017-09-29
·
CVE-2008-2832
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Full Revolution aspWebCalendar 2008
Description
The issue concerns an unrestricted file upload vulnerability. This vulnerability allows remote attackers to upload and execute arbitrary code via the
FILE1 parameter in an "uploadfileprocess" action, likely followed by a direct request to the file in "calendar/eventimages/".Recommendations
For Full Revolution aspWebCalendar 2008, restrict access to the "uploadfileprocess" action and the "calendar/eventimages/" directory to prevent arbitrary code execution. Consider implementing validation and restrictions on file uploads to mitigate the risk of exploitation.
Exploit
Correção
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Full Revolution Aspwebcalendar 2008