CVE-2008-1495

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
25/03/2008
Last modified:
09/04/2025

Description

Unrestricted file upload vulnerability in administrer/produits.php in PEEL, possibly 3.x and earlier, allows remote authenticated administrators to upload and execute arbitrary PHP files via a modified content type in an ajout action, as demonstrated by (1) image/gif and (2) application/pdf.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:peel:peel:1.0b:*:*:*:*:*:*:*
cpe:2.3:a:peel:peel:2.6:*:*:*:*:*:*:*
cpe:2.3:a:peel:peel:2.7:*:*:*:*:*:*:*