Vulnerability Description
Unrestricted file upload vulnerability in app/lib/mlf.pl in C-BOARD Moyuku before 1.03b3 allows remote attackers to execute arbitrary code by uploading a file with a \0 character in its name.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| C-Board Moyuku Project | C-Board Moyuku | <= 1.03 |
References
- http://jvn.jp/en/jp/JVN73261710/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2015-000018Vendor Advisory
- http://sourceforge.jp/projects/cb-moyuku/news/Vendor Advisory
- http://jvn.jp/en/jp/JVN73261710/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2015-000018Vendor Advisory
- http://sourceforge.jp/projects/cb-moyuku/news/Vendor Advisory
FAQ
What is CVE-2015-0877?
CVE-2015-0877 is a vulnerability with a CVSS score of 7.5 (HIGH). Unrestricted file upload vulnerability in app/lib/mlf.pl in C-BOARD Moyuku before 1.03b3 allows remote attackers to execute arbitrary code by uploading a file with a \0 character in its name.
How severe is CVE-2015-0877?
CVE-2015-0877 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-0877?
Check the references section above for vendor advisories and patch information. Affected products include: C-Board Moyuku Project C-Board Moyuku.