7.5
CVSSv2

CVE-2008-2267

Published: 16/05/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Incomplete blacklist vulnerability in javaUpload.php in Postlet in the FileManager module in CMS Made Simple 1.2.4 and previous versions allows remote malicious users to execute arbitrary code by uploading a file with a name ending in (1) .jsp, (2) .php3, (3) .cgi, (4) .dhtml, (5) .phtml, (6) .php5, or (7) .jar, then accessing it via a direct request to the file in modules/FileManager/postlet/.

Vulnerable Product Search on Vulmon Subscribe to Product

cms made simple cms made simple 1.2.4

Exploits

<?php /* --------------------------------------------------------------------------- CMS Made Simple <= 124 (FileManager module) Arbitrary File Upload Exploit --------------------------------------------------------------------------- author: EgiX mail: n0b0d13s[at]gmail[dot]com link: wwwcmsmadesimpleorg/ d ...