CVE-2010-1514
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/06/2010
Last modified:
11/04/2025
Description
Unrestricted file upload vulnerability in TomatoCMS 2.0.6 and earlier allows remote authenticated users, with certain privileges, to execute arbitrary PHP code by uploading an image file, and then accessing it via a direct request to the file in an unspecified directory.
Impact
Base Score 2.0
6.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:tomatocms:tomatocms:*:*:*:*:*:*:*:* | 2.0.6 (including) | |
cpe:2.3:a:tomatocms:tomatocms:2.0.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:tomatocms:tomatocms:2.0.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:tomatocms:tomatocms:2.0.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:tomatocms:tomatocms:2.0.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:tomatocms:tomatocms:2.0.3.1430:*:*:*:*:*:*:* | ||
cpe:2.3:a:tomatocms:tomatocms:2.0.3.1622:*:*:*:*:*:*:* | ||
cpe:2.3:a:tomatocms:tomatocms:2.0.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:tomatocms:tomatocms:2.0.5:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://holisticinfosec.org/content/view/148/45/
- http://secunia.com/advisories/39680
- http://secunia.com/secunia_research/2010-57/
- http://www.securityfocus.com/bid/40544
- http://holisticinfosec.org/content/view/148/45/
- http://secunia.com/advisories/39680
- http://secunia.com/secunia_research/2010-57/
- http://www.securityfocus.com/bid/40544