CVE

CVE-2008-0805

Severity:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
19/02/2008
Last modified:
29/09/2017

Description

Unrestricted file upload vulnerability in image.php in PHPizabi 0.848b C1 HFP1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension from the event page, then accessing it via a direct request to the file in system/cache/pictures.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:reality:medias_phpizabi:0.848b:*:*:*:*:*:*:*