7.5
CVSSv2

CVE-2008-2742

Published: 17/06/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload in the mcpuk file editor (atk/attributes/fck/editor/filemanager/browser/mcpuk/connectors/php/config.php) in Achievo 1.2.0 up to and including 1.3.2 allows remote malicious users to execute arbitrary code by uploading a file with .php followed by a safe extension, then accessing it via a direct request to the file in the Achievo root directory. NOTE: this is only a vulnerability in environments that support multiple extensions, such as Apache with the mod_mime module enabled.

Vulnerable Product Search on Vulmon Subscribe to Product

achievo achievo 1.2.0

achievo achievo 1.2.1

achievo achievo 1.3.0

achievo achievo 1.3.1

achievo achievo 1.3.2

Exploits

<?php /* ----------------------------------------------------------------- Achievo <= 132 (fckeditor) Remote Arbitrary File Upload Exploit ----------------------------------------------------------------- author: EgiX mail: n0b0d13s[at]gmail[dot]com link: wwwachievoorg/ details: works only with a specific ...