PT-2008-4271 · Full Revolution · Full Revolution Aspwebcalendar 2008
Alemin_Krali
·
Published
2008-06-24
·
Updated
2017-09-29
·
CVE-2008-2832
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Full Revolution aspWebCalendar 2008
Description
The issue concerns an unrestricted file upload vulnerability. This vulnerability allows remote attackers to upload and execute arbitrary code via the
FILE1 parameter in an "uploadfileprocess" action, likely followed by a direct request to the file in "calendar/eventimages/".Recommendations
For Full Revolution aspWebCalendar 2008, restrict access to the "uploadfileprocess" action and the "calendar/eventimages/" directory to prevent arbitrary code execution. Consider implementing validation and restrictions on file uploads to mitigate the risk of exploitation.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Full Revolution Aspwebcalendar 2008