SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-7215

The Image Manager in MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to rename arbitrary files and cause a denial of service via modified file[NewFile][name], file[NewFile][tmp_name], and file[NewFile][size] parameters…

MEDIUM 5.8EPSS 1.81%

Does this matter?

Lower severity and a low EPSS score (1.81%). Track it; it rarely justifies an emergency change on its own.

Description

The Image Manager in MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to rename arbitrary files and cause a denial of service via modified file[NewFile][name], file[NewFile][tmp_name], and file[NewFile][size] parameters in a FileUpload command, which are used to modify equivalent variables in $_FILES that are accessed when the is_uploaded_file check fails.

CVSS 2.0
5.8 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
EPSS
1.81% probability · 77th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
mambo-foundation/mambo · brilaps/mostlyce
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.