CVE-2008-7215
The Image Manager in MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to rename arbitrary files and cause a denial of service via modified file[NewFile][name], file[NewFile][tmp_name], and file[NewFile][size] parameters…
Does this matter?
Lower severity and a low EPSS score (1.81%). Track it; it rarely justifies an emergency change on its own.
Description
The Image Manager in MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to rename arbitrary files and cause a denial of service via modified file[NewFile][name], file[NewFile][tmp_name], and file[NewFile][size] parameters in a FileUpload command, which are used to modify equivalent variables in $_FILES that are accessed when the is_uploaded_file check fails.
- CVSS 2.0
- 5.8 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
- EPSS
- 1.81% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- mambo-foundation/mambo · brilaps/mostlyce
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2008-02/0444.htmlVendor Advisory
- http://forum.mambo-foundation.org/showthread.php?t=10158
- http://osvdb.org/42532Exploit
- http://secunia.com/advisories/28670Vendor Advisory
- http://www.bugreport.ir/index_33.htmExploit
- http://www.securityfocus.com/archive/1/487128/100/200/threaded
- http://www.securityfocus.com/bid/27472
- http://www.vupen.com/english/advisories/2008/0325Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39986
- http://archives.neohapsis.com/archives/bugtraq/2008-02/0444.htmlVendor Advisory
- http://forum.mambo-foundation.org/showthread.php?t=10158
- http://osvdb.org/42532Exploit
- http://secunia.com/advisories/28670Vendor Advisory
- http://www.bugreport.ir/index_33.htmExploit
- http://www.securityfocus.com/archive/1/487128/100/200/threaded
- http://www.securityfocus.com/bid/27472
- http://www.vupen.com/english/advisories/2008/0325Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39986
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.