Vulnerabilities > CVE-2009-2238 - Unspecified vulnerability in Dmxready Registration Manager 1.1

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
dmxready
exploit available

Summary

Unrestricted file upload vulnerability in includes/shared_scripts/wysiwyg_editor/assetmanager/assetmanager.asp in DMXReady Registration Manager 1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in assets/webblogmanager.

Vulnerable Configurations

Part Description Count
Application
Dmxready
1

Exploit-Db

descriptionDMXReady Registration Manager 1.1 Arbitrary File Upload Vulnerability. CVE-2009-2238. Webapps exploit for asp platform
fileexploits/asp/webapps/8749.txt
idEDB-ID:8749
last seen2016-02-01
modified2009-05-20
platformasp
port
published2009-05-20
reporterSecuritylab.ir
sourcehttps://www.exploit-db.com/download/8749/
titleDMXReady Registration Manager 1.1 - Arbitrary File Upload Vulnerability
typewebapps