8.8

CVE-2019-9581

Exploit
phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitrary Web/custom-favicon.php PHP code, because Presenters/Admin/ManageThemePresenter.php does not ensure an image file extension.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TwinkletoessoftwareBooked Version2.7.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 13.73% 0.96
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

http://packetstormsecurity.com/files/165263/Booked-Scheduler-2.7.5-Shell-Upload.html
Third Party Advisory
Exploit
VDB Entry
https://pentest.com.tr/exploits/Booked-2-7-5-Remote-Command-Execution-Metasploit.html
Patch
Third Party Advisory
Exploit
https://sourceforge.net/p/phpscheduleit/source/ci/c5a86a279d888bd4362e4b4f61acedc054f99c39/
Patch
https://www.exploit-db.com/exploits/46486
Third Party Advisory
Exploit
VDB Entry