6
CVE-2010-1514
- EPSS 0.95%
- Veröffentlicht 15.06.2010 14:30:01
- Zuletzt bearbeitet 16.06.2026 23:18:32
- Quelle PSIRT-CNA@flexerasoftware.com
- CVE-Watchlists
- Unerledigt
Unrestricted file upload vulnerability in TomatoCMS 2.0.6 and earlier allows remote authenticated users, with certain privileges, to execute arbitrary PHP code by uploading an image file, and then accessing it via a direct request to the file in an unspecified directory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.95% | 0.566 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6 | 6.8 | 6.4 |
AV:N/AC:M/Au:S/C:P/I:P/A:P
|
http://holisticinfosec.org/content/view/148/45/
http://secunia.com/advisories/39680
http://secunia.com/secunia_research/2010-57/
http://www.securityfocus.com/bid/40544