5
CVSSv2

CVE-2002-1087

Published: 04/10/2002 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The scripts (1) createdir.php, (2) removedir.php and (3) uploadfile.php for ezContents 1.41 and previous versions do not check credentials, which allows remote malicious users to create or delete directories and upload files via a direct HTTP POST request.

Vulnerable Product Search on Vulmon Subscribe to Product

visualshapers ezcontents