Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-6684
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-6684

Description:
Unrestricted file upload vulnerability in editimage.php in Apartment Search Script allows remote attackers to execute arbitrary code by uploading a file with an executable extension and a GIF header, then accessing this file via a direct request to a renamed file in Member_Admin/logo/.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/46283

MILW0RM
  http://www.milw0rm.com/exploits/6956

BID
  32065


Return to the previous page.