PT-2009-2220 · Revou · Revou Micro Blogging Tclone Plugin

S.W.A.T

·

Published

2009-04-24

·

Updated

2017-09-29

·

CVE-2008-6751

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: ReVou Micro Blogging TClone plugin (affected versions not specified)
Description: The issue concerns an unrestricted file upload vulnerability. This allows remote attackers to execute arbitrary code by uploading a file with an executable extension and then accessing it directly. The vulnerability is specifically in the index.php file of the TClone plugin.
Recommendations: For the TClone plugin, consider disabling the file upload functionality in index.php until a patch is available to prevent remote attackers from executing arbitrary code. Restrict access to the settings/my photo directory to minimize the risk of exploitation. Avoid using the file upload feature in the TClone plugin until the issue is resolved.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-6751

Affected Products

Revou Micro Blogging Tclone Plugin