VulnerabilityModified
CVE-2008-3093
Unrestricted file upload vulnerability in ImperialBB 2.3.5 and earlier allows remote authenticated users to upload and execute arbitrary PHP code by placing a .php filename in the Upload_Avatar parameter and sending the image/gif content type.
MEDIUM 6.5EPSS 2.17%
Does this matter?
Lower severity and a low EPSS score (2.17%). Track it; it rarely justifies an emergency change on its own.
Description
Unrestricted file upload vulnerability in ImperialBB 2.3.5 and earlier allows remote authenticated users to upload and execute arbitrary PHP code by placing a .php filename in the Upload_Avatar parameter and sending the image/gif content type.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 2.17% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- phplizardo/imperialbb
- Source
- cve@mitre.org
References
- http://phplizardo.breizh-web.net/blog/2008/07/05/advisory-1-imperialbb
- http://secunia.com/advisories/30939Vendor Advisory
- http://www.securityfocus.com/bid/30100
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43608
- https://www.exploit-db.com/exploits/6008
- http://phplizardo.breizh-web.net/blog/2008/07/05/advisory-1-imperialbb
- http://secunia.com/advisories/30939Vendor Advisory
- http://www.securityfocus.com/bid/30100
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43608
- https://www.exploit-db.com/exploits/6008
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.