ALERT CVE-2008-6822
Description : Unrestricted file upload vulnerability in uploadp.php in New Earth Programming Team (NEPT) imgupload (aka Image Uploader) 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension and a modified content type, then accessing this file via a direct request, as demonstrated by an upload with an image/jpeg content type. NOTE: some of these details are obtained from third party information. Read more ...
VECTOR BRIEF
| FULL CVSS v2 VECTOR | |
| (AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:ND/RC:ND/CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND) | |
| BASE METRICS | |
Access Vector : Network * Access Complexity : Low * Authentification : None Required * |
Confidentiality : Partial * Integrity : Partial * Availability : Partial * |
| * Required | |
| ENVIRONMENTAL METRICS | |
Confidentiality Requirement : Not Defined Integrity Requirement : Not Defined Availability Requirement : Not Defined |
Collateral Damage Potential : Not Defined Target Distribution : Not Defined |
| TEMPORAL METRICS | |
Exploitability : Not Defined Remediation Level : Not Defined Report Confidence : Not Defined |
|
Security Dashboard



CVSS Base Score : 7.5

