Executive Summary
This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Informations | |||
---|---|---|---|
Name | CVE-2005-0254 | First vendor Publication | 2005-05-02 |
Vendor | Cve | Last vendor Modification | 2025-01-16 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:N/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 4.3 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
BibORB 1.3.2, and possibly earlier versions, does not properly enforce a restriction for uploading only PDF and PS files, which allows remote attackers to upload arbitrary files that are presented to other users with PDF or PS icons, which may trick some users into downloading and executing those files. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0254 |
CAPEC : Common Attack Pattern Enumeration & Classification
Id | Name |
---|---|
CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
CAPEC-122 | Exploitation of Authorization |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-434 | Unrestricted Upload of File with Dangerous Type (CWE/SANS Top 25) |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 2 |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
13916 | BibORB Arbitrary File Upload BibORB contains a flaw that may allow a remote attacker to upload arbitrary files. The issue is due to program not properly sanitizing user input supplied to the upload file. This may allow an attacker to include a file from a remote host that contains arbitrary commands which is linked with standard icons of a PDF or PS file. Users may be fooled to click the icon and download malicious code instead of the desired PDF or PS file. |
Sources (Detail)
Source | Url |
---|
Alert History
Date | Informations |
---|---|
2025-01-16 21:22:18 |
|
2024-11-28 23:22:17 |
|
2024-11-28 12:06:43 |
|
2024-02-02 21:28:27 |
|
2024-01-27 00:28:11 |
|
2021-05-04 12:02:45 |
|
2021-04-22 01:02:58 |
|
2020-05-23 00:16:19 |
|
2016-10-18 12:01:34 |
|
2013-05-11 11:20:46 |
|