6.8
CVSSv2

CVE-2008-7157

Published: 02/09/2009 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in EkinBoard 1.1.0 and previous versions allows remote malicious users to execute arbitrary code by uploading an avatar file with an executable extension followed by a safe extension, then accessing it via a direct request to the file in uploaded/avatars/.

Vulnerable Product Search on Vulmon Subscribe to Product

ekinboard ekinboard

Exploits

----[ EkinBoard Remote File Upload / Auth Bypass ITDefenceru Antichatru ] EkinBoard >= 110 Remote File Upload / Auth Bypass Eugene Minaev underwater@itdefenceru ___________________________________________________________________ ____/ __ __ _______________________ _______ _______________ \ \ \ / \ / ...