5
CVE-2002-1841
- EPSS 2.16%
- Veröffentlicht 31.12.2002 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:00:09
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The document management module in NOLA 1.1.1 and 1.1.2 does not restrict the types of files that are uploaded, which allows remote attackers to upload and execute arbitrary PHP files with extensions such as .php4.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.16% | 0.798 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
http://marc.info/?l=vuln-dev&m=102511114021370&w=2
http://marc.info/?l=vuln-dev&m=102520790718208&w=2
http://online.securityfocus.com/archive/1/280340
http://www.iss.net/security_center/static/9438.php
http://www.securityfocus.com/bid/5116