CVE Vulnerabilities

CVE-2010-1514

Published: Jun 15, 2010 | Modified: Jun 18, 2010
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Unrestricted file upload vulnerability in TomatoCMS 2.0.6 and earlier allows remote authenticated users, with certain privileges, to execute arbitrary PHP code by uploading an image file, and then accessing it via a direct request to the file in an unspecified directory.

Affected Software

Name Vendor Start Version End Version
Tomatocms Tomatocms * 2.0.6 (including)
Tomatocms Tomatocms 2.0.0 (including) 2.0.0 (including)
Tomatocms Tomatocms 2.0.1 (including) 2.0.1 (including)
Tomatocms Tomatocms 2.0.2 (including) 2.0.2 (including)
Tomatocms Tomatocms 2.0.3 (including) 2.0.3 (including)
Tomatocms Tomatocms 2.0.3.1430 (including) 2.0.3.1430 (including)
Tomatocms Tomatocms 2.0.3.1622 (including) 2.0.3.1622 (including)
Tomatocms Tomatocms 2.0.4 (including) 2.0.4 (including)
Tomatocms Tomatocms 2.0.5 (including) 2.0.5 (including)

References