CVE Database
/

CVE-2009-4140

Back to search

CVE-2009-4140

Published: Dec 22, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer, as used in Piwik 0.2.35 through 0.4.3, Woopra Analytics Plugin before 1.4.3.2, and possibly other products, when register_globals is enabled, allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension through the name parameter with the code in the HTTP_RAW_POST_DATA parameter, then accessing it via a direct request to the file in tmp-upload-images/.

VendorProductVersions

n/a

n/a

affected
n/a

References

37314
vdb-entry
x_refsource_BID
59051
vdb-entry
x_refsource_OSVDB
55160
third-party-advisory
x_refsource_SECUNIA
37078
third-party-advisory
x_refsource_SECUNIA
24969
exploit
x_refsource_EXPLOIT-DB
55162
third-party-advisory
x_refsource_SECUNIA
ADV-2009-2966
vdb-entry
x_refsource_VUPEN
37911
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now