PT-2008-5978 · Php Nuke · Php-Nuke

Publicado

2008-10-28

·

Atualizado

2019-07-01

·

CVE-2008-4767

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PHP-Nuke (affected versions not specified)
Description The issue allows remote attackers to potentially execute arbitrary code by uploading files with certain extensions, including .htm, .html, or .txt, and then accessing them directly. However, it is unclear how the upload of .html or .txt files could lead to arbitrary code execution, as this might be a legitimate functionality.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-4767

Produtos afetados

Php-Nuke