← Back

CVE-2009-0372

nvd nist
Published: Jan 30, 2009Modified: Apr 23, 2026

JSON object

Loading...
6.5
Vector
AV:N/AC:L/Au:S/C:P/I:P/A:P
Exploitability: 8.0 / Impact: 6.4
Source: NVD

Description

Unrestricted file upload vulnerability in index.php in Miltenovik Manojlo MemHT Portal 4.0.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension and an image content type via a users editProfile action, then accessing this file via a direct request to the file in images/avatar/uploaded/.

Affected (33)

Products: Memht: Memht Portal
1 product
Memht Portal
Configuration A
33 vulnerable
Vulnerable SoftwareAffected Versions
Memht
Up to 4.0.1
Version 1.0 final
Version 1.5 full
Version 1.5 update
Version 2.0 full
Version 2.0 update
Version 2.5 full
Version 2.5 update
Version 2.9 full
Version 2.9 update
Version 3.0 full
Version 3.0 update
Version 3.1
Version 3.1 full
Version 3.1 update
Version 3.2 update
Version 3.3 full
Version 3.3 update
Version 3.4.5
Version 3.4.5 full
Version 3.4.5 update
Version 3.4
Version 3.4 full
Version 3.4 update
Version 3.5.0 full
Version 3.6.0
Version 3.6.5
Version 3.7.0
Version 3.7.5
Version 3.8.0
Version 3.8.1
Version 3.8.5
Version 3.9.0

References (8)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.