8.8
CVSSv3

CVE-2017-14704

Published: 26/09/2017 Updated: 10/10/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Laravel Airbnb Clone 1.0 allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/profile.

Vulnerable Product Search on Vulmon Subscribe to Product

claydip airbnb clone 1.0

Exploits

# # # # # # Exploit Title: Claydip Laravel Airbnb Clone 10 - Arbitrary File Upload # Dork: N/A # Date: 22092017 # Vendor Homepage: wwwclaydipcom/ # Software Link: wwwclaydipcom/airbnb-clonehtml # Demo: wwwclaydipcom/airbnb_demohtml # Version: N/A # Category: Webapps # Tested on: WiN7_x64/KaLiLinuX_x64 # CVE: CVE- ...
Claydip Airbnb Clone version 10 suffers from an arbitrary file upload vulnerability ...