CVE-2008-0233 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.2% (pctl 82)
Patch early
A public exploit exists.
Description
Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.21% — more likely to be exploited than 82% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-01-11 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| zero cms | zero cms |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | ZeroCMS 1.0 Alpha - Arbitrary File Upload / SQL Injection | 2008-01-08 |
References
→ the Explorer · watch your stack · NVD