PT-2008-4422 · Benja · Benja Cms

Cwh

·

Published

2008-07-02

·

Updated

2018-10-11

·

CVE-2008-2988

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Benja CMS version 0.1
Description The issue concerns an unrestricted file upload vulnerability. This allows remote attackers to upload and execute arbitrary PHP files. The attack is carried out via unspecified vectors, followed by a direct request to the file in the billeder/ directory.
Recommendations For Benja CMS version 0.1, restrict access to the admin/upload.php file to prevent unauthorized file uploads. As a temporary workaround, consider disabling the file upload functionality in admin/upload.php until a patch is available.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-2988

Affected Products

Benja Cms