CVE-2008-2832
HIGH 10.0EPSS 11.8%
Unrestricted file upload vulnerability in calendar_admin.asp in Full Revolution aspWebCalendar 2008 allows remote attackers to upload and execute arbitrary code via the FILE1 parameter in an uploadfileprocess action, probably followed by a direct request to the file in calendar/eventimages/.
- CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 11.80% chance of exploitation in the next 30 days, 96th percentile
- Published
- 2008-06-24
- Updated
- 2024-08-07