7.5
CVSSv2

CVE-2005-2885

Published: 14/09/2005 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Downloads page in MAXdev MD-Pro 1.0.73, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which could allow remote malicious users to bypass file extension checks and execute arbitrary commands by uploading a file with a different extension, as demonstrated using .inc files.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

maxdev md-pro 1.0.73

Exploits

source: wwwsecurityfocuscom/bid/14750/info MAXdev MD-Pro is prone to an arbitrary remote file upload vulnerability This issue is due to a failure in the application to properly sanitize user-supplied input This issue is due to a design error in the application that uses a blacklist technique, saying what file extensions can not be uplo ...