Meilad File upload script (up.php) mod for phpBB 2.0.x does not properly limit the types of files that can be uploaded, which allows remote authenticated users to execute arbitrary commands by uploading PHP files, then directly requesting them from the uploads directory.
References
Link | Resource |
---|---|
http://marc.info/?l=bugtraq&m=111299353030534&w=2 | |
http://securitytracker.com/id?1013671 | Vendor Advisory |
http://www.defacers.com.mx/advisories/2.txt | URL Repurposed |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2005-04-12T04:00:00
Updated: 2016-10-17T13:57:01
Reserved: 2005-04-12T00:00:00
Link: CVE-2005-1047
JSON object: View
NVD Information
Status : Modified
Published: 2005-04-07T04:00:00.000
Modified: 2024-02-14T01:17:43.863
Link: CVE-2005-1047
JSON object: View
Redhat Information
No data.
CWE