PT-2009-2000 · Ezonescripts · Ezonescripts Living Local

Bgh7

·

Published

2009-03-26

·

Updated

2017-09-29

·

CVE-2008-6530

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions eZoneScripts Living Local version 1.1
Description The issue allows remote authenticated administrators to execute arbitrary PHP code by uploading a file with an executable extension to the editimage.php file, and then accessing it via a direct request to the uploaded file. This can be achieved by exploiting an unrestricted file upload vulnerability.
Recommendations For version 1.1, restrict access to the editimage.php file to prevent unauthorized file uploads, and consider implementing validation to only allow uploading of files with specific, non-executable extensions. As a temporary workaround, consider disabling the file upload functionality in editimage.php until a more comprehensive fix is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2008-6530

Affected Products

Ezonescripts Living Local