6.8
CVSSv2

CVE-2008-7062

Published: 25/08/2009 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in admin/index.php in Download Manager module 1.0 for LoveCMS 1.6.2 Final allows remote malicious users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/.

Vulnerable Product Search on Vulmon Subscribe to Product

lovecms lovecms 1.6.2

Exploits

<?php /** * LoveCMS 162 Final (Download Manager v10) Arbitrary File Upload Exploit * Discovered && Exploited by cOndemned * * Download: * wwwthethinkingmannet/modules/download_manager/?id=16 * * Description: * This exploit allows attacker to upload any type of file [no extension * filtration] ex php shell * * Uploader i ...