CVE-2005-1957
mtnpeak.net File Upload Manager does not properly check user authentication for certain actions, which allows remote attackers to provide a modified base64-encoded file parameter and (1) read arbitrary files via the "view" action or (2) delete arbitrary…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.65%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
mtnpeak.net File Upload Manager does not properly check user authentication for certain actions, which allows remote attackers to provide a modified base64-encoded file parameter and (1) read arbitrary files via the "view" action or (2) delete arbitrary files via the del action.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.65% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- adam mmedici/file upload manager
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2005-06/0116.html
- http://marc.info/?l=bugtraq&m=111868578006615&w=2
- http://www.osvdb.org/17435
- http://www.osvdb.org/20258
- http://archives.neohapsis.com/archives/bugtraq/2005-06/0116.html
- http://marc.info/?l=bugtraq&m=111868578006615&w=2
- http://www.osvdb.org/17435
- http://www.osvdb.org/20258
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.