CVE-2008-3093

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
09/07/2008
Last modified:
09/04/2025

Description

Unrestricted file upload vulnerability in ImperialBB 2.3.5 and earlier allows remote authenticated users to upload and execute arbitrary PHP code by placing a .php filename in the Upload_Avatar parameter and sending the image/gif content type.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:phplizardo:imperialbb:*:*:*:*:*:*:*:* 2.3.5 (including)