CVE Vulnerabilities

CVE-2010-1514

Published: Jun 15, 2010 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Unrestricted file upload vulnerability in TomatoCMS 2.0.6 and earlier allows remote authenticated users, with certain privileges, to execute arbitrary PHP code by uploading an image file, and then accessing it via a direct request to the file in an unspecified directory.

Affected Software

Name Vendor Start Version End Version
Tomatocms Tomatocms * 2.0.6 (including)
Tomatocms Tomatocms 2.0.0 (including) 2.0.0 (including)
Tomatocms Tomatocms 2.0.1 (including) 2.0.1 (including)
Tomatocms Tomatocms 2.0.2 (including) 2.0.2 (including)
Tomatocms Tomatocms 2.0.3 (including) 2.0.3 (including)
Tomatocms Tomatocms 2.0.3.1430 (including) 2.0.3.1430 (including)
Tomatocms Tomatocms 2.0.3.1622 (including) 2.0.3.1622 (including)
Tomatocms Tomatocms 2.0.4 (including) 2.0.4 (including)
Tomatocms Tomatocms 2.0.5 (including) 2.0.5 (including)

References