CVE Vulnerabilities

CVE-2008-7026

Published: Aug 21, 2009 | Modified: Oct 11, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension as an avatar, then accessing it via a direct request to the file in (1) student/avatars/ or (2) professor/avatars/.

Affected Software

Name Vendor Start Version End Version
Efront Efrontlearning * 3.5.1 (including)
Efront Efrontlearning 3.1.0 (including) 3.1.0 (including)
Efront Efrontlearning 3.1.2 (including) 3.1.2 (including)
Efront Efrontlearning 3.1.3 (including) 3.1.3 (including)
Efront Efrontlearning 3.1.4 (including) 3.1.4 (including)
Efront Efrontlearning 3.5.0 (including) 3.5.0 (including)
Efront Efrontlearning 3.5.0-beta1 (including) 3.5.0-beta1 (including)
Efront Efrontlearning 3.5.0-beta2 (including) 3.5.0-beta2 (including)
Efront Efrontlearning 3.5.0-beta3 (including) 3.5.0-beta3 (including)
Efront Efrontlearning 3.5.0-beta4 (including) 3.5.0-beta4 (including)

References