PT-2009-2521 · Unknown · Pre Real Estate Listings

Backdoor

·

Published

2009-08-24

·

Updated

2017-09-29

·

CVE-2008-7052

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Pre Real Estate Listings (affected versions not specified)
Description The issue concerns an unrestricted file upload vulnerability. This allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo. The exploitation involves accessing the uploaded file directly via a request to the file in re images/.
Recommendations For all affected versions, consider restricting file uploads to only allow non-executable file extensions as a temporary mitigation measure. Restrict access to the re images/ directory to minimize the risk of exploitation. Avoid using the profile logo upload feature until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-7052

Affected Products

Pre Real Estate Listings