9

CVE-2008-5663

Multiple unrestricted file upload vulnerabilities in Kusaba 1.0.4 and earlier allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension using (1) load_receiver.php or (2) a shipainter action to paint_save.php, then accessing the uploaded file via a direct request to this file in their user directory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
KusabaKusaba Version <= 1.0.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.27% 0.927
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://securityreason.com/securityalert/4782
http://www.securityfocus.com/bid/31668
http://www.securityfocus.com/bid/31685
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/45793
https://exchange.xforce.ibmcloud.com/vulnerabilities/45794
https://www.exploit-db.com/exploits/6706
https://www.exploit-db.com/exploits/6711