9
CVE-2008-5663
- EPSS 6.27%
- Veröffentlicht 19.12.2008 01:51:59
- Zuletzt bearbeitet 16.06.2026 23:00:45
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple unrestricted file upload vulnerabilities in Kusaba 1.0.4 and earlier allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension using (1) load_receiver.php or (2) a shipainter action to paint_save.php, then accessing the uploaded file via a direct request to this file in their user directory.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 6.27% | 0.927 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9 | 8 | 10 |
AV:N/AC:L/Au:S/C:C/I:C/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://securityreason.com/securityalert/4782
http://www.securityfocus.com/bid/31668
http://www.securityfocus.com/bid/31685
https://exchange.xforce.ibmcloud.com/vulnerabilities/45793
https://exchange.xforce.ibmcloud.com/vulnerabilities/45794
https://www.exploit-db.com/exploits/6706
https://www.exploit-db.com/exploits/6711