CVE-2008-6913
07.08.2009, 19:00
Unrestricted file upload vulnerability in editresume_next.php in Zeeways ZEEJOBSITE 2.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a photo in a profile edit action, then accessing the file via a direct request to jobseekers/logos/.Enginsight
Vendor | Product | Version |
---|---|---|
zeeways | zeejobsite | 2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References