← Back

CVE-2008-7026

nvd nist
Published: Aug 21, 2009Modified: Apr 23, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension as an avatar, then accessing it via a direct request to the file in (1) student/avatars/ or (2) professor/avatars/.

Affected (10)

Efront
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Efrontlearning
Up to 3.5.1
Version 3.1.0
Version 3.1.2
Version 3.1.3
Version 3.1.4
Version 3.5.0
Version 3.5.0 beta1
Version 3.5.0 beta2
Version 3.5.0 beta3
Version 3.5.0 beta4

Related CWEs

References (12)

Source: cve@mitre.org
Source: cve@mitre.org
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.