7.5
CVSSv2

CVE-2007-6668

Published: 08/01/2008 Updated: 19/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

admin/uploadgames.php in MySpace Content Zone (MCZ) 3.x does not require administrative privileges, which allows remote malicious users to perform unrestricted file uploads, as demonstrated by uploading (1) a .php file and (2) a .php%00.jpeg file.

Vulnerable Product Search on Vulmon Subscribe to Product

peergoal myspace content zone

Exploits

---------------------------------------------------- [+-MySpace Content Zone RFi-+] ---------------------------------------------------- Found By Don & breaker_unit ---------------------------------------------------- Vuln file: /admin/uploadgamesphp Fix: secure admin area Dork: "Powered by MySpace Content Zone" go to /admin/uploadgamesp ...