7.1

CVE-2008-5677

Exploit
Unrestricted file upload vulnerability in Kwalbum 2.0.4, 2.0.2, and earlier, when PICS_PATH is located in the web root, allows remote authenticated users with upload capability to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file under items/, related to the ReplaceBadFilenameChars function in include/ItemAdder.php.  NOTE: some of these details are obtained from third party information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
KwalbumKwalbum Version <= 2.0.2
KwalbumKwalbum Version0.5.1
KwalbumKwalbum Version0.5.2
KwalbumKwalbum Version0.5.3
KwalbumKwalbum Version0.5.4
KwalbumKwalbum Version0.5.6
KwalbumKwalbum Version0.5.7
KwalbumKwalbum Version0.5.8
KwalbumKwalbum Version0.5.9
KwalbumKwalbum Version0.5.10
KwalbumKwalbum Version0.5.11
KwalbumKwalbum Version0.5.12
KwalbumKwalbum Version0.6.0
KwalbumKwalbum Version0.6.1
KwalbumKwalbum Version0.6.4
KwalbumKwalbum Version0.6.5
KwalbumKwalbum Version0.6.6
KwalbumKwalbum Version0.6.7
KwalbumKwalbum Version0.6.8
KwalbumKwalbum Version0.6.9
KwalbumKwalbum Version0.6.10
KwalbumKwalbum Version0.6.11
KwalbumKwalbum Version0.6.12
KwalbumKwalbum Version0.6.13
KwalbumKwalbum Version0.6.14
KwalbumKwalbum Version0.6.15
KwalbumKwalbum Version0.6.16
KwalbumKwalbum Version0.7.0
KwalbumKwalbum Version0.7.1
KwalbumKwalbum Version0.8.0
KwalbumKwalbum Version0.9.0
KwalbumKwalbum Version0.9.1
KwalbumKwalbum Version0.9.2
KwalbumKwalbum Version0.9.3
KwalbumKwalbum Version0.9.4
KwalbumKwalbum Version1.0
KwalbumKwalbum Version2.0
KwalbumKwalbum Version2.0.1
KwalbumKwalbum Version2.0.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.97% 0.881
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.1 3.9 10
AV:N/AC:H/Au:S/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.