7.5
CVE-2004-1404
- EPSS 2.47%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Attachment Mod 2.3.10 module for phpBB, when used with Apache mod_mime, does not properly handle files with multiple file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Opentools ≫ Attachment Mod Version2.3.4
Opentools ≫ Attachment Mod Version2.3.5
Opentools ≫ Attachment Mod Version2.3.6
Opentools ≫ Attachment Mod Version2.3.7
Opentools ≫ Attachment Mod Version2.3.8
Opentools ≫ Attachment Mod Version2.3.9
Opentools ≫ Attachment Mod Version2.3.10
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.47% | 0.838 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|