6.8
CVSSv2

CVE-2008-7026

Published: 21/08/2009 Updated: 11/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and previous versions allows remote malicious users to execute arbitrary code by uploading a file with an executable extension as an avatar, then accessing it via a direct request to the file in (1) student/avatars/ or (2) professor/avatars/.

Vulnerable Product Search on Vulmon Subscribe to Product

efrontlearning efront 3.5.0

efrontlearning efront 3.1.4

efrontlearning efront 3.1.3

efrontlearning efront

efrontlearning efront 3.1.2

efrontlearning efront 3.1.0

Exploits

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- eFront <= 351 / build 2710: Remote File Inclusion Vulnerability -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- $ Program: eFront $ File affected: studentpagephp / professorpage $ Version: 351 / build 2710 $ Download: wwwefrontlearningnet Found b ...