Back
CVE-2005-4422
Unrestricted file upload vulnerability in toendaCMS before 0.6.2 Stable allows remote authenticated administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in data/images/albums.
Published: Dec 20, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| toenda_software_development | toendacms | 0.6.1 |
GitHub Security Advisory GHSA-89q9-wwr5-f2mf
Unrestricted file upload vulnerability in toendaCMS before 0.6.2 Stable allows remote...
References (8)
- http://secunia.com/advisories/17471 Patch, Vendor Advisory
- http://www.securityfocus.com/archive/1/415975 Patch, Vendor Advisory
- http://www.securityfocus.com/bid/15351 Patch
- http://www.toenda.com/de/data/files/Software/toendaCMS_Version_0.6.0_Stable/toendaCMS_0.6.2.1_Stable.zip
- http://secunia.com/advisories/17471 Patch, Vendor Advisory
- http://www.securityfocus.com/archive/1/415975 Patch, Vendor Advisory
- http://www.securityfocus.com/bid/15351 Patch
- http://www.toenda.com/de/data/files/Software/toendaCMS_Version_0.6.0_Stable/toendaCMS_0.6.2.1_Stable.zip
Risk Scores
CVSS Score
6.5 / 10
EPSS Score
2.08%
Top 20% most likely to be exploited
Threat Score
26.6 / 100
Data Sources
NVD
EPSS
GitHub