6.5
CVSSv2

CVE-2008-7088

Published: 26/08/2009 Updated: 29/09/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in upload.php in PhotoPost vBGallery 2.4.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the file in a certain path. NOTE: this may be the same vulnerability as CVE-2008-0251, but this is not clear due to lack of details from the vendor.

Vulnerable Product Search on Vulmon Subscribe to Product

photopost photopost vbgallery 2.4.2

Exploits

vBulletin PhotoPost vBGallery v2x Remote File Upload Found by : Cold z3ro e-mail : exploiter@hackteachorg Home page : wwwHackps ============================== exploit usage : localhost/Forum/$gallery_path/uploadphp here the exploiter can upload php shell via this script by renamed it's name to $namephpwmv but first he should ...