PT-2008-3721 · Unknown · Project-Based Calendaring System
Gold_M
·
Published
2008-05-14
·
Updated
2017-09-29
·
CVE-2008-2216
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Project-Based Calendaring System (PBCS) version 0.7.1
Description:
The issue concerns an unrestricted file upload vulnerability. This vulnerability is located in the src/yopy upload.php file and allows remote authenticated users to upload arbitrary files to the tmp/uploads directory.
Recommendations:
For version 0.7.1, restrict access to the src/yopy upload.php file to prevent unauthorized file uploads until a patch is available. Consider implementing validation and restrictions on uploaded files to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Project-Based Calendaring System