Unrated severityNVD Advisory· Published Jun 15, 2010· Updated Apr 29, 2026
CVE-2010-1514
CVE-2010-1514
Description
Unrestricted file upload vulnerability in TomatoCMS 2.0.6 and earlier allows remote authenticated users, with certain privileges, to execute arbitrary PHP code by uploading an image file, and then accessing it via a direct request to the file in an unspecified directory.
Affected products
9cpe:2.3:a:tomatocms:tomatocms:*:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:tomatocms:tomatocms:*:*:*:*:*:*:*:*range: <=2.0.6
- cpe:2.3:a:tomatocms:tomatocms:2.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:tomatocms:tomatocms:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:tomatocms:tomatocms:2.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:tomatocms:tomatocms:2.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:tomatocms:tomatocms:2.0.3.1430:*:*:*:*:*:*:*
- cpe:2.3:a:tomatocms:tomatocms:2.0.3.1622:*:*:*:*:*:*:*
- cpe:2.3:a:tomatocms:tomatocms:2.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:tomatocms:tomatocms:2.0.5:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- secunia.com/advisories/39680nvdVendor Advisory
- secunia.com/secunia_research/2010-57/nvdVendor Advisory
- holisticinfosec.org/content/view/148/45/nvd
- www.securityfocus.com/bid/40544nvd
News mentions
0No linked articles in our index yet.