Security Advisory

CVE-2008-6951

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2009-08-12 10:00:00
Last updated 2024-08-07 11:49:02
Assigner mitre
State PUBLISHED

Description

MauryCMS 0.53.2 and earlier does not require administrative authentication for Editors/fckeditor/editor/filemanager/browser/default/browser.html, which allows remote attackers to upload arbitrary files via a direct request.