Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5rx6-m8fr-g79v

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Unrestricted file upload vulnerability in editimage.php in Apartment Search Script allows remote attackers to execute arbitrary code by uploading a file with an executable extension and a GIF header, then accessing this file via a direct request to a renamed file in Member_Admin/logo/.

Unrestricted file upload vulnerability in editimage.php in Apartment Search Script allows remote attackers to execute arbitrary code by uploading a file with an executable extension and a GIF header, then accessing this file via a direct request to a renamed file in Member_Admin/logo/.

EPSS

Процентиль: 78%
0.01188
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
почти 17 лет назад

Unrestricted file upload vulnerability in editimage.php in Apartment Search Script allows remote attackers to execute arbitrary code by uploading a file with an executable extension and a GIF header, then accessing this file via a direct request to a renamed file in Member_Admin/logo/.

EPSS

Процентиль: 78%
0.01188
Низкий

Дефекты

CWE-20