PT-2009-2634 · Unknown · Page Manager

Cwh Underground

·

Published

2009-09-08

·

Updated

2017-09-29

·

CVE-2008-7167

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Page Manager version 2006-02-04
Description The issue allows remote attackers to execute arbitrary code by uploading a file with an executable extension to the upload.php file, and then accessing it via a direct request.
Recommendations For Page Manager version 2006-02-04, consider restricting access to the upload.php file to prevent unauthorized file uploads until a fix is available. As a temporary workaround, restrict the types of files that can be uploaded to prevent executable files from being uploaded.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-7167

Affected Products

Page Manager