7.5
CVSSv2

CVE-2007-6650

Published: 04/01/2008 Updated: 15/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in fisheye/upload.php in Bitweaver R2 CMS allows remote malicious users to upload arbitrary files by using the image/gif content type, and possibly other image and PDF content types, as demonstrated by uploading a .htaccess file.

Vulnerable Product Search on Vulmon Subscribe to Product

bitweaver r2 cms

Exploits

########################## WwWBugReportir ######################### # # AmnPardaz Security Research Team # # Title: Bitweaver R2 CMS # Vendor: wwwbitweaverorg # Bugs: source code disclosure, arbitrary file upload # Vulnerable Version: 2 (prior versions also may be affected) # Exploitation: Remote with browser # Fix Available: No! ## ...