CVE-2004-1448: Medium severity jetbox jetbox one cms vulnerability
Published Dec 31, 2004
·Updated
Jetbox One 2.0.8 and possibly other versions allow remote attackers with Author privileges in the IMAGES module to upload PHP files and execute arbitrary code.
Affected Software
1 affected component
Jetbox Jetbox One Cms=2.0.8
Event History
Dec 31, 2004
CVE Published
05:00 AM
Feb 13, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1448?
CVE-2004-1448 is considered a critical vulnerability due to the ability of remote attackers to execute arbitrary code.
2
How do I fix CVE-2004-1448?
To fix CVE-2004-1448, upgrade to the latest version of Jetbox One that addresses this vulnerability.
3
Who is affected by CVE-2004-1448?
Anyone using Jetbox One CMS version 2.0.8 or possibly earlier versions is affected by CVE-2004-1448.
4
What type of attack does CVE-2004-1448 allow?
CVE-2004-1448 allows remote attackers to upload and execute PHP files due to inadequate validation of file uploads.
5
What privileges are required to exploit CVE-2004-1448?
Attackers need to have Author privileges in the IMAGES module to exploit CVE-2004-1448.