Record summary

CVE-2008-2832 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.

Description

Unrestricted file upload vulnerability in calendar_admin.asp in Full Revolution aspWebCalendar 2008 allows remote attackers to upload and execute arbitrary code via the FILE1 parameter in an uploadfileprocess action, probably followed by a direct request to the file in calendar/eventimages/.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBAspWebCalendar 2008 - Arbitrary File UploadExploitDB exploitby Alemin_KraliNot analyzed1 file
ExploitDB

PoC details

References

5