PT-2008-3721 · Unknown · Project-Based Calendaring System

Gold_M

·

Published

2008-05-14

·

Updated

2017-09-29

·

CVE-2008-2216

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Project-Based Calendaring System (PBCS) version 0.7.1
Description: The issue concerns an unrestricted file upload vulnerability. This vulnerability is located in the src/yopy upload.php file and allows remote authenticated users to upload arbitrary files to the tmp/uploads directory.
Recommendations: For version 0.7.1, restrict access to the src/yopy upload.php file to prevent unauthorized file uploads until a patch is available. Consider implementing validation and restrictions on uploaded files to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-2216

Affected Products

Project-Based Calendaring System