10
CVSSv2

CVE-2008-4509

Published: 09/10/2008 Updated: 29/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Unrestricted file upload vulnerability in processFiles.php in FOSS Gallery Admin and FOSS Gallery Public 1.0 beta allows remote malicious users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the root directory.

Vulnerable Product Search on Vulmon Subscribe to Product

foss gallery foss gallery 1.0

Exploits

# FOSS Gallery Public <= 10 Arbitrary Upload / Information c99 Expoit # url: downloadssourceforgenet/fossgallery/ # # Author: JosS # mail: sys-project[at]hotmail[dot]com # site: spanish-hackerscom # team: Spanish Hackers Team - [SHT] # # This was written for educational purpose Use it at your own risk # Author will be not res ...
#! /usr/bin/perl # -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- # FOSS Gallery Admin Version <= 10 / Remote Arbitrary Upload Vulnerability # -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- # Program: FOSS Gallery Admin Version # Version: <= 10 # File affected: processFilesphp # Downlo ...
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= FOSS Gallery Public Version <= 10 / Arbitrary file upload Vulnerabilities -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= Program: FOSS Gallery Public Version Version: <= 10 File affected: processFilesphp Download: sourceforgenet/ ...