CVE-2008-3592
11.08.2008, 23:41
Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension to a directory specified in the destination parameter, then accessing the uploaded file via a direct request, as demonstrated using workspace/masters/.
Vendor | Product | Version |
---|---|---|
21degrees | symphony | 𝑥 ≤ 1.7.01 |
21degrees | symphony | 1.1 |
21degrees | symphony | 1.5 |
21degrees | symphony | 1.5.05 |
21degrees | symphony | 1.5.06 |
21degrees | symphony | 1.6.02 |
21degrees | symphony | 1.7 |
𝑥
= Vulnerable software versions
References