6.5
CVSSv2

CVE-2008-4366

Published: 30/09/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in the image upload component in Camera Life 2.6.2b4 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in a user directory under images/photos/upload.

Vulnerable Product Search on Vulmon Subscribe to Product

camera life camera life 2.6.2b4

Exploits

[+] CameraLife-262b4 Arbitrary File Upload Vulnerability [+] Author:Mi4night [+] Version:cameralife-262b4 [+] Download Script: [+] sourceforgenet/project/showfilesphp?group_id=70910&package_id=70316&release_id=628868 [+] Exploit: [+] 127001/cameralife/images/photos/upload/Mi4night/yourshellphp [+] Description: [ ...