7.5
CVSSv2

CVE-2008-6490

Published: 19/03/2009 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

function/update_xml.php in FLABER 1.1 and previous versions allows remote malicious users to overwrite arbitrary files by specifying the target filename in the target_file parameter. NOTE: this can be leveraged for code execution by overwriting a PHP file, as demonstrated using function/upload_file.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

flysforum flaber

Exploits

<?php /* -------------------------------------------------- FLABER <= 11 RC1 Remote Command Execution Exploit -------------------------------------------------- author: EgiX mail: n0b0d13s[at]gmail[dot]com link: sourceforgenet/projects/flaber [-] vulnerable code in /function/update_xmlphp 12 $target_fi ...