Vulnerability Description
Unrestricted file upload vulnerability in toendaCMS before 0.6.2 Stable allows remote authenticated administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in data/images/albums.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Toenda Software Development | Toendacms | 0.6.1 |
References
- http://secunia.com/advisories/17471PatchVendor Advisory
- http://www.securityfocus.com/archive/1/415975PatchVendor Advisory
- http://www.securityfocus.com/bid/15351Patch
- http://www.toenda.com/de/data/files/Software/toendaCMS_Version_0.6.0_Stable/toen
- http://secunia.com/advisories/17471PatchVendor Advisory
- http://www.securityfocus.com/archive/1/415975PatchVendor Advisory
- http://www.securityfocus.com/bid/15351Patch
- http://www.toenda.com/de/data/files/Software/toendaCMS_Version_0.6.0_Stable/toen
FAQ
What is CVE-2005-4422?
CVE-2005-4422 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Unrestricted file upload vulnerability in toendaCMS before 0.6.2 Stable allows remote authenticated administrators to execute arbitrary code by uploading a file with an executable extension, then acce...
How severe is CVE-2005-4422?
CVE-2005-4422 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-4422?
Check the references section above for vendor advisories and patch information. Affected products include: Toenda Software Development Toendacms.