CVE-2009-3447
RADactive I-Load < 2008.2.5.0 - Unauthenticated Arbitrary File Upload and Remote Code Execution via Predictable Filename
Title source: llmDescription
Unrestricted file upload vulnerability in RADactive I-Load before 2008.2.5.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, and then sending a request for a predictable filename during a short time window.
References (5)
Core 5
Core References
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/506555/100/0/threaded
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23807
Various Sources x_refsource_confirm
http://radnet.radactive.com/forum/Default.aspx?g=posts&t=339
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/58197
Various Sources x_refsource_misc
https://www.sec-consult.com/files/20090917-0_RADactive_I-Load_Multiple_Vulnerabilities.txt
Scores
EPSS
0.0167
EPSS Percentile
73.8%
Details
CWE
CWE-362
Status
published
Products (46)
radactive/i-load
1.6.3
radactive/i-load
1.6.3.1
radactive/i-load
1.6.3.2
radactive/i-load
1.6.3.3
radactive/i-load
1.7.0.0
radactive/i-load
1.7.0.1
radactive/i-load
1.7.0.2
radactive/i-load
1.7.0.3
radactive/i-load
1.7.0.4
radactive/i-load
1.7.0.5
... and 36 more
Published
Sep 29, 2009
Tracked Since
Feb 18, 2026