Various Affected Software (Various Versions) - Arbitrary File Upload
highUnrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer, as used in Piwik 0.2.35 through 0.4.3, Woopra Analytics Plugin before 1.4.3.2, and possibly other products, when register_globals is enabled, allows remote authenticated users to execute arbitrary c...
- CVSS:
- 8.8
- Affected:
- 0.2.35 – 0.4.3
- Fixed in:
- 0.4.4
- Disclosed:
- Oct 21, 2009