CVE-2008-7157
02.09.2009, 17:30
Unrestricted file upload vulnerability in EkinBoard 1.1.0 and earlier allows remote attackers to execute arbitrary code by uploading an avatar file with an executable extension followed by a safe extension, then accessing it via a direct request to the file in uploaded/avatars/.Enginsight
Vendor | Product | Version |
---|---|---|
ekinboard | ekinboard | 𝑥 ≤ 1.1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration