ID

VAR-200809-0366


CVE

CVE-2008-4366


TITLE

Camera Life Arbitrary image upload component vulnerable to arbitrary code execution

Trust: 0.8

sources: JVNDB: JVNDB-2008-003484

DESCRIPTION

Unrestricted file upload vulnerability in the image upload component in Camera Life 2.6.2b4 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in a user directory under images/photos/upload. The issue occurs because the application fails to sanitize user-supplied input. Camera Life 2.6.2b4 is vulnerable; other versions may also be affected

Trust: 1.98

sources: NVD: CVE-2008-4366 // JVNDB: JVNDB-2008-003484 // BID: 31456 // VULHUB: VHN-34491

AFFECTED PRODUCTS

vendor:camera lifemodel:camera lifescope:eqversion:2.6.2b4

Trust: 2.4

vendor:cameramodel:life camera life 2.6.2b4scope: - version: -

Trust: 0.3

sources: BID: 31456 // JVNDB: JVNDB-2008-003484 // CNNVD: CNNVD-200809-454 // NVD: CVE-2008-4366

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2008-4366
value: MEDIUM

Trust: 1.0

NVD: CVE-2008-4366
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-200809-454
value: MEDIUM

Trust: 0.6

VULHUB: VHN-34491
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2008-4366
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-34491
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-34491 // JVNDB: JVNDB-2008-003484 // CNNVD: CNNVD-200809-454 // NVD: CVE-2008-4366

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-34491 // JVNDB: JVNDB-2008-003484 // NVD: CVE-2008-4366

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200809-454

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-200809-454

CONFIGURATIONS

sources: JVNDB: JVNDB-2008-003484

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-34491

PATCH

title:Top Pageurl:http://fdcl.sourceforge.net/

Trust: 0.8

sources: JVNDB: JVNDB-2008-003484

EXTERNAL IDS

db:NVDid:CVE-2008-4366

Trust: 2.8

db:BIDid:31456

Trust: 2.0

db:EXPLOIT-DBid:6594

Trust: 1.7

db:SREASONid:4344

Trust: 1.7

db:JVNDBid:JVNDB-2008-003484

Trust: 0.8

db:XFid:45492

Trust: 0.6

db:MILW0RMid:6594

Trust: 0.6

db:CNNVDid:CNNVD-200809-454

Trust: 0.6

db:VULHUBid:VHN-34491

Trust: 0.1

sources: VULHUB: VHN-34491 // BID: 31456 // JVNDB: JVNDB-2008-003484 // CNNVD: CNNVD-200809-454 // NVD: CVE-2008-4366

REFERENCES

url:http://www.securityfocus.com/bid/31456

Trust: 1.7

url:http://securityreason.com/securityalert/4344

Trust: 1.7

url:https://www.exploit-db.com/exploits/6594

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/45492

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2008-4366

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2008-4366

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/45492

Trust: 0.6

url:http://www.milw0rm.com/exploits/6594

Trust: 0.6

url:http://fdcl.sourceforge.net/

Trust: 0.3

sources: VULHUB: VHN-34491 // BID: 31456 // JVNDB: JVNDB-2008-003484 // CNNVD: CNNVD-200809-454 // NVD: CVE-2008-4366

CREDITS

Mi4night

Trust: 0.3

sources: BID: 31456

SOURCES

db:VULHUBid:VHN-34491
db:BIDid:31456
db:JVNDBid:JVNDB-2008-003484
db:CNNVDid:CNNVD-200809-454
db:NVDid:CVE-2008-4366

LAST UPDATE DATE

2025-04-10T23:15:41.736000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-34491date:2017-09-29T00:00:00
db:BIDid:31456date:2015-05-07T17:23:00
db:JVNDBid:JVNDB-2008-003484date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200809-454date:2009-01-29T00:00:00
db:NVDid:CVE-2008-4366date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:VULHUBid:VHN-34491date:2008-09-30T00:00:00
db:BIDid:31456date:2008-09-27T00:00:00
db:JVNDBid:JVNDB-2008-003484date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200809-454date:2008-09-30T00:00:00
db:NVDid:CVE-2008-4366date:2008-09-30T23:24:53.683