10
CVSSv2

CVE-2008-2832

Published: 24/06/2008 Updated: 29/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Unrestricted file upload vulnerability in calendar_admin.asp in Full Revolution aspWebCalendar 2008 allows remote malicious users to upload and execute arbitrary code via the FILE1 parameter in an uploadfileprocess action, probably followed by a direct request to the file in calendar/eventimages/.

Vulnerable Product Search on Vulmon Subscribe to Product

fullrevolution aspwebcalendar2008

Exploits

Title:AspWebCalendar 2008 Remote File Upload Vulnerability # Discovered by : Alemin_Krali # Dork :calendarasp?eventdetail [sitecom]/path/calendar_adminasp?action=uploadfile ==>>> upload your Asp shell [sitecom]/path/calendar/eventimages/yourshellasp ==>>> your address upload form <FORM ENCTYPE='multip ...