Vulnerabilities > CVE-2008-6660 - Unspecified vulnerability in Ozerov Bigdump 029B

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
ozerov
exploit available

Summary

Unrestricted file upload vulnerability in bigdump.php in Alexey Ozerov BigDump 0.29b allows remote attackers to execute arbitrary code by uploading a file with an executable extension followed by a .sql extension, then accessing this file via a direct request. NOTE: some of these details are obtained from third party information.

Vulnerable Configurations

Part Description Count
Application
Ozerov
1

Exploit-Db

descriptionBigDump 0.35b - Arbitrary Upload. CVE-2008-6660. Webapps exploit for php platform
idEDB-ID:32479
last seen2016-02-03
modified2014-03-24
published2014-03-24
reporterfelipe andrian
sourcehttps://www.exploit-db.com/download/32479/
titleBigDump 0.35b - Arbitrary Upload