Vulnerability Description
Unrestricted file upload vulnerability in image_upload.php in the SimpleBoard (com_simpleboard) component 1.0.1 and earlier for Mambo allows remote attackers to execute arbitrary code by uploading a file with an executable extension and an image/jpeg content type, then accessing this file via a direct request to the file in components/com_simpleboard/, a different vulnerability than CVE-2006-3528.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jan De Graaff | Com Simpleboard | <= 1.0.1 |
| Mambo | Mambo | All versions |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/31981Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46223
- https://www.exploit-db.com/exploits/6868
- http://www.securityfocus.com/bid/31981Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46223
- https://www.exploit-db.com/exploits/6868
FAQ
What is CVE-2008-6814?
CVE-2008-6814 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Unrestricted file upload vulnerability in image_upload.php in the SimpleBoard (com_simpleboard) component 1.0.1 and earlier for Mambo allows remote attackers to execute arbitrary code by uploading a f...
How severe is CVE-2008-6814?
CVE-2008-6814 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-6814?
Check the references section above for vendor advisories and patch information. Affected products include: Jan De Graaff Com Simpleboard, Mambo Mambo.