6.5
CVSSv2

CVE-2005-4423

Published: 20/12/2005 Updated: 05/09/2008
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in PHPFM prior to 0.2.3 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension to an accessible directory, as demonstrated using a file with a .php extension, aka "upload phpshell."

Vulnerable Product Search on Vulmon Subscribe to Product

Exploits

source: wwwsecurityfocuscom/bid/15335/info PHPFM is prone to an arbitrary file upload vulnerability An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the Web server process This may facilitate unauthorized access or privilege escalation; other attacks are also possible ------------- ...