PT-2005-3506 · Ezupload · Eupload

Published

2005-08-17

·

Updated

2011-03-08

·

CVE-2005-2616

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ezUpload version 2.2
Description The issue allows remote attackers to execute arbitrary code via the path parameter to several PHP files, including "initialize.php", "customize.php", "form.php", and "index.php".
Recommendations For ezUpload version 2.2, consider restricting access to the vulnerable PHP files until a patch is available. As a temporary workaround, avoid using the path parameter in the affected files.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-2616

Affected Products

Eupload