PoC Index

CVE-2008-1495

MEDIUM 6.5EPSS 2.0%

Unrestricted file upload vulnerability in administrer/produits.php in PEEL, possibly 3.x and earlier, allows remote authenticated administrators to upload and execute arbitrary PHP files via a modified content type in an ajout action, as demonstrated by (1) image/gif and (2) application/pdf.

CVSS v2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
2.00% chance of exploitation in the next 30 days, 79th percentile
Published
2008-03-25
Updated
2024-08-07

ExploitDB entries (1)

References

Related