Multiple PHP file include vulnerabilities in ezUpload 2.2 allow remote attackers to execute arbitrary code via the path parameter to (1) initialize.php, (2) customize.php, (3) form.php, or (4) index.php.
References
Link | Resource |
---|---|
http://packetstorm.linuxsecurity.com/0508-exploits/ezuploadRemote.txt | Exploit |
http://www.securiteam.com/exploits/5JP0J15GKU.html | Exploit Vendor Advisory |
http://www.securityfocus.com/bid/14534 | Exploit |
http://secunia.com/advisories/16434 | Vendor Advisory |
http://securitytracker.com/id?1014723 | |
http://www.vupen.com/english/advisories/2005/1379 |
Configurations
Information
Published : 2005-08-16 21:00
Updated : 2011-03-07 18:24
NVD link : CVE-2005-2616
Mitre link : CVE-2005-2616
JSON object : View
CWE
Products Affected
ezupload
- ezupload