6.8
CVSSv2

CVE-2009-1483

Published: 29/04/2009 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in upload-file.php in Adam Patterson Studio Lounge Address Book 2.5, as reachable from index2.php, allows remote malicious users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in profiles/.

Vulnerable Product Search on Vulmon Subscribe to Product

studiolounge address book 2.5

Exploits

Address Book 25 (profile) Remote Shell Upload Vulnerability bug found by Jose Luis Gongora Fernandez (aka) JosS contact: sys-project[at]hotmailcom website: wwwhack0wncom/ - download: wwwstudioloungenet/2007/08/17/address-book-25 - vuln file: upload-filephp The upload-filephp doesn't check the type of archive and you ...