6.8
CVSSv2

CVE-2012-4036

Published: 27/08/2012 Updated: 14/02/2024
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in admin.php in PBBoard 2.1.4 allows remote administrators to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in the addons directory. NOTE: this vulnerability can be leveraged by remote attackers using CVE-2012-1216.

Vulnerable Product Search on Vulmon Subscribe to Product

pbboard pbboard 2.1.4

Exploits

source: wwwsecurityfocuscom/bid/54916/info PBBoard is prone to multiple security vulnerabilities including: 1 Multiple SQL-injection vulnerabilities 2 A security-bypass vulnerability 3 An arbitrary file upload vulnerability Exploiting these issues could allow an attacker to carry out unauthorized actions on the underlying datab ...
PBBoard version 214 suffers from improper authentication, improper access control, and remote SQL injection vulnerabilities ...