CVE-2008-3239
published 2008-07-21CVE-2008-3239: Unrestricted file upload vulnerability in the writeLogEntry function in system/v_cron_proc.php in PHPizabi 0.848b C1 HFP1, when register_globals is enabled…
PriorityP357critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
5.17%
91.4th percentile
Unrestricted file upload vulnerability in the writeLogEntry function in system/v_cron_proc.php in PHPizabi 0.848b C1 HFP1, when register_globals is enabled, allows remote attackers to upload and execute arbitrary code via a filename in the CONF[CRON_LOGFILE] parameter and file contents in the CONF[LOCALE_LONG_DATE_TIME] parameter.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| phpizabi | phpizabi | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://secunia.com/advisories/31127http://securityreason.com/securityalert/4022http://www.securityfocus.com/bid/30257https://exchange.xforce.ibmcloud.com/vulnerabilities/43856https://www.exploit-db.com/exploits/6085http://secunia.com/advisories/31127http://securityreason.com/securityalert/4022http://www.securityfocus.com/bid/30257https://exchange.xforce.ibmcloud.com/vulnerabilities/43856https://www.exploit-db.com/exploits/6085
2008-07-21
Published