PT-2008-4271 · Full Revolution · Full Revolution Aspwebcalendar 2008

Alemin_Krali

·

Published

2008-06-24

·

Updated

2017-09-29

·

CVE-2008-2832

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Full Revolution aspWebCalendar 2008
Description The issue concerns an unrestricted file upload vulnerability. This vulnerability allows remote attackers to upload and execute arbitrary code via the FILE1 parameter in an "uploadfileprocess" action, likely followed by a direct request to the file in "calendar/eventimages/".
Recommendations For Full Revolution aspWebCalendar 2008, restrict access to the "uploadfileprocess" action and the "calendar/eventimages/" directory to prevent arbitrary code execution. Consider implementing validation and restrictions on file uploads to mitigate the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-2832

Affected Products

Full Revolution Aspwebcalendar 2008