VulnerabilityModified
CVE-2007-2733
Unrestricted file upload vulnerability in Jetbox CMS allows remote authenticated users with author privileges to upload arbitrary scripts via unspecified vectors, which can be accessed in webfiles/.
MEDIUM 6.0EPSS 0.95%
Does this matter?
Lower severity and a low EPSS score (0.95%). Track it; it rarely justifies an emergency change on its own.
Description
Unrestricted file upload vulnerability in Jetbox CMS allows remote authenticated users with author privileges to upload arbitrary scripts via unspecified vectors, which can be accessed in webfiles/. NOTE: this issue might be a duplicate of CVE-2004-1448.
- CVSS 2.0
- 6.0 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
- EPSS
- 0.95% probability · 59th percentile
- CISA KEV
- Not listed
- Affected
- jetbox/jetbox cms
- Source
- cve@mitre.org
References
- http://osvdb.org/37450
- http://securityreason.com/securityalert/2711
- http://www.securityfocus.com/archive/1/468681/100/0/threaded
- http://www.securityfocus.com/bid/23996
- http://osvdb.org/37450
- http://securityreason.com/securityalert/2711
- http://www.securityfocus.com/archive/1/468681/100/0/threaded
- http://www.securityfocus.com/bid/23996
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.