7.5
CVE-2004-1404
- EPSS 2.92%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:07:38
- Erkennungen
Attachment Mod 2.3.10 module for phpBB, when used with Apache mod_mime, does not properly handle files with multiple file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Opentools ≫ Attachment Mod Version 2.3.4
Opentools ≫ Attachment Mod Version 2.3.5
Opentools ≫ Attachment Mod Version 2.3.6
Opentools ≫ Attachment Mod Version 2.3.7
Opentools ≫ Attachment Mod Version 2.3.8
Opentools ≫ Attachment Mod Version 2.3.9
Opentools ≫ Attachment Mod Version 2.3.10
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.92% | 0.852 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/13421/
http://www.securityfocus.com/bid/11893
http://marc.info/?l=bugtraq&m=110321557806215&w=2
http://www.opentools.de/board/viewtopic.php?t=3590
https://exchange.xforce.ibmcloud.com/vulnerabilities/18438