Security Advisory

CVE-2008-7215

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2009-09-11 16:00:00
Last updated 2024-08-07 11:56:14
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The Image Manager in MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to rename arbitrary files and cause a denial of service via modified file[NewFile][name], file[NewFile][tmp_name], and file[NewFile][size] parameters in a FileUpload command, which are used to modify equivalent variables in $_FILES that are accessed when the is_uploaded_file check fails.