7.5
CVSSv2

CVE-2008-0233

Published: 11/01/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and previous versions allows remote malicious users to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg.

Vulnerable Product Search on Vulmon Subscribe to Product

zero cms zero cms 1.0_alpha

Exploits

[*]~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~[*] | ____ __________ __ ____ __ | | /_ | ____ |__\_____ \ _____/ |_ /_ |/ |_ | | | |/ \ | | _(__ <_/ ___\ __\ ______ | \ __\ | | | | | \ | |/ \ \___| | /_____/ | ...