Multiple PHP file include vulnerabilities in ezUpload 2.2 allow remote attackers to execute arbitrary code via the path parameter to (1) initialize.php, (2) customize.php, (3) form.php, or (4) index.php.
References
Link | Resource |
---|---|
http://packetstorm.linuxsecurity.com/0508-exploits/ezuploadRemote.txt | Exploit |
http://secunia.com/advisories/16434 | Vendor Advisory |
http://securitytracker.com/id?1014723 | |
http://www.securiteam.com/exploits/5JP0J15GKU.html | Exploit Vendor Advisory |
http://www.securityfocus.com/bid/14534 | Exploit |
http://www.vupen.com/english/advisories/2005/1379 |
Configurations
History
No history.
Information
Published : 2005-08-17 04:00
Updated : 2024-02-28 10:42
NVD link : CVE-2005-2616
Mitre link : CVE-2005-2616
CVE.ORG link : CVE-2005-2616
JSON object : View
Products Affected
ezupload
- ezupload
CWE