Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2007-6668 (MySpace_Content_Zone)

BugsAlert Home > CVE-2007-6668 (MySpace_Content_Zone)
 
 

admin/uploadgames.php in MySpace Content Zone (MCZ) 3.x does not require administrative privileges, which allows remote attackers to perform unrestricted file uploads, as demonstrated by uploading (1) a .php file and (2) a .php%00.jpeg file.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6668

Learn more about CVE-2007-6668 (MySpace_Content_Zone)
 
Tags: cve-2007-6668 myspace content zone

Related Items

      CVE-2008-3699 (Amarok)

      CVE-2008-5157 (tau)

      CVE-2008-3162 (FFmpeg)

      Plone Cross-Site Request Forgery Vulnerability

      Savings tip: Free internet security package - Scotsman

      Mandriva: Updated Qt4 packages fix vulnerability in

      VUPEN - Active Web Mail "TabOpenQuickTab1" SQL Injection Vulnerability

 

Pixel