Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4rrg-j6g5-6x9x

Опубликовано: 18 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.4
CVSS3: 8.8

Описание

File Thingie 2.5.7 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious PHP zip archives to the web server. Attackers can create a custom PHP payload, upload and unzip it, and then execute arbitrary system commands through a crafted PHP script with a command parameter.

File Thingie 2.5.7 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious PHP zip archives to the web server. Attackers can create a custom PHP payload, upload and unzip it, and then execute arbitrary system commands through a crafted PHP script with a command parameter.

EPSS

Процентиль: 36%
0.00151
Низкий

9.4 Critical

CVSS4

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
nvd
около 2 месяцев назад

File Thingie 2.5.7 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious PHP zip archives to the web server. Attackers can create a custom PHP payload, upload and unzip it, and then execute arbitrary system commands through a crafted PHP script with a command parameter.

EPSS

Процентиль: 36%
0.00151
Низкий

9.4 Critical

CVSS4

8.8 High

CVSS3

Дефекты

CWE-434