- Description
- Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension to a directory specified in the destination parameter, then accessing the uploaded file via a direct request, as demonstrated using workspace/masters/.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 8.5
- Impact score
- 10
- Exploitability score
- 6.8
- Vector string
- AV:N/AC:M/Au:S/C:C/I:C/A:C
- nvd@nist.gov
- CWE-94
- Hype score
- Not currently trending
- Comment
- Successful exploitation of this vulnerability requires valid administrator credentials. See CVE-2008-3591 for more information.
- Impact
- -
- Solution
- -
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:21degrees:symphony:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FE2EEB23-8CD7-4035-87F1-EC01E61CE7C3",
"versionEndIncluding": "1.7.01"
},
{
"criteria": "cpe:2.3:a:21degrees:symphony:1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A06D221D-9BC8-480B-ADF6-4251C0F1E6D9"
},
{
"criteria": "cpe:2.3:a:21degrees:symphony:1.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "20EEBB01-8615-4FD7-888B-E369084267FA"
},
{
"criteria": "cpe:2.3:a:21degrees:symphony:1.5.05:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9B6D10C3-F68F-4366-9594-BD338A33F8DF"
},
{
"criteria": "cpe:2.3:a:21degrees:symphony:1.5.06:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C42DFAF4-F81A-467C-AD4D-1095E7A932EF"
},
{
"criteria": "cpe:2.3:a:21degrees:symphony:1.6.02:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "48BE3B5E-72F6-4FA1-B976-0FD59EB6FFC8"
},
{
"criteria": "cpe:2.3:a:21degrees:symphony:1.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "90B1FA15-86CB-4C11-85EC-20C6A5529827"
}
],
"operator": "OR"
}
]
}
]