7.5
CVSSv2

CVE-2008-2574

Published: 06/06/2008 Updated: 11/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in admin/Editor/imgupload.php in FlashBlog 0.31 beta allows remote malicious users to execute arbitrary code by uploading a .php file, then accessing it via a direct request to the file in tus_imagenes/.

Vulnerable Product Search on Vulmon Subscribe to Product

flashblog flashblog 0.31

Exploits

FlashBlog beta031 Remote File Upload Vulnerability # Author : ilker kandemir aka MEFISTO # Dork : inurl:flashbloghtml or inurl:/flashblog/ # Website : wwwdumencinet, wwwcoderxorg [sitecom]/admin/Editor/imguploadphp ==>>> upload your c99 shell [sitecom]/tus_imagenes/c99php ==>>> your address Tnx: ...