CVE-2008-6367
HIGH 8.5EPSS 3.4%
Unrestricted file upload vulnerability in Photos/create_album.php in Social Groupie allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in Member_images/.
- CVSS v2.0
- 8.5 HIGH
AV:N/AC:M/Au:S/C:C/I:C/A:C - EPSS
- 3.40% chance of exploitation in the next 30 days, 88th percentile
- Published
- 2009-03-02
- Updated
- 2024-08-07