CVE-2009-0372
30.01.2009, 19:30
Unrestricted file upload vulnerability in index.php in Miltenovik Manojlo MemHT Portal 4.0.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension and an image content type via a users editProfile action, then accessing this file via a direct request to the file in images/avatar/uploaded/.Enginsight
Vendor | Product | Version |
---|---|---|
memht | memht_portal | 𝑥 ≤ 4.0.1 |
memht | memht_portal | 1.0:final |
memht | memht_portal | 1.5:full |
memht | memht_portal | 1.5:update |
memht | memht_portal | 2.0:full |
memht | memht_portal | 2.0:update |
memht | memht_portal | 2.5:full |
memht | memht_portal | 2.5:update |
memht | memht_portal | 2.9:full |
memht | memht_portal | 2.9:update |
memht | memht_portal | 3.0:full |
memht | memht_portal | 3.0:update |
memht | memht_portal | 3.1 |
memht | memht_portal | 3.1:full |
memht | memht_portal | 3.1:update |
memht | memht_portal | 3.2:update |
memht | memht_portal | 3.3:full |
memht | memht_portal | 3.3:update |
memht | memht_portal | 3.4 |
memht | memht_portal | 3.4:full |
memht | memht_portal | 3.4:update |
memht | memht_portal | 3.4.5 |
memht | memht_portal | 3.4.5:full |
memht | memht_portal | 3.4.5:update |
memht | memht_portal | 3.5.0:full |
memht | memht_portal | 3.6.0 |
memht | memht_portal | 3.6.5 |
memht | memht_portal | 3.7.0 |
memht | memht_portal | 3.7.5 |
memht | memht_portal | 3.8.0 |
memht | memht_portal | 3.8.1 |
memht | memht_portal | 3.8.5 |
memht | memht_portal | 3.9.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References