peter bassill · operator
$ cve CVE-2008-2833 JSON

CVE-2008-2833 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 4.1% (pctl 91)

Patch early

A public exploit exists.

Description

admin/upload.php in le.cms 1.4 and earlier allows remote attackers to bypass administrative authentication, and upload and execute arbitrary files in images/, via a nonzero value for the submit0 parameter in conjunction with filenames in the filename and upload parameters.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS4.13% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2008-06-24
Last modified2026-06-16

Affected (1)

VendorProduct
worldlevelle.cms

Public exploits

SourceTitleDate
exploit-dbLE.CMS 1.4 - Arbitrary File Upload2008-06-21

References

→ the Explorer  ·  watch your stack  ·  NVD