Vulnerabilities > CVE-2008-6822 - Unspecified vulnerability in Newearthpt Imgupload 1.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
newearthpt
exploit available

Summary

Unrestricted file upload vulnerability in uploadp.php in New Earth Programming Team (NEPT) imgupload (aka Image Uploader) 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension and a modified content type, then accessing this file via a direct request, as demonstrated by an upload with an image/jpeg content type. NOTE: some of these details are obtained from third party information.

Vulnerable Configurations

Part Description Count
Application
Newearthpt
1

Exploit-Db

descriptionNEPT Image Uploader 1.0 Arbitrary Shell Upload Vulnerability. CVE-2008-6822. Webapps exploit for php platform
fileexploits/php/webapps/6830.txt
idEDB-ID:6830
last seen2016-02-01
modified2008-10-24
platformphp
port
published2008-10-24
reporterDentrasi
sourcehttps://www.exploit-db.com/download/6830/
titleNEPT Image Uploader 1.0 - Arbitrary Shell Upload Vulnerability
typewebapps