6.8
CVSSv2

CVE-2008-6084

Published: 06/02/2009 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in pages/download.php in Iamma Simple Gallery 1.0 and 2.0 allows remote malicious users to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in the uploads directory.

Vulnerable Product Search on Vulmon Subscribe to Product

.matteoiammarrone iamma simple gallery 2.0

.matteoiammarrone iamma simple gallery 1.0

Exploits

Found by: X0r Iamma Simple Gallery Arbitrary File Upload Version: 1,2 (?) Email: evolutionteamx0[at]gmail[dot]com Script Download:wwwmatteoiammarronecom/public/modulesphp?name=Downloads&d_op=getit&lid=4 Script Download 2:wwwpierotofyit/pages/downloadphp?filename=100p97q116r97s47t112a114i111f103g114h97n109o115l47m80b72c ...