Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7xcv-cvmj-qpgr

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

The document management module in NOLA 1.1.1 and 1.1.2 does not restrict the types of files that are uploaded, which allows remote attackers to upload and execute arbitrary PHP files with extensions such as .php4.

The document management module in NOLA 1.1.1 and 1.1.2 does not restrict the types of files that are uploaded, which allows remote attackers to upload and execute arbitrary PHP files with extensions such as .php4.

EPSS

Процентиль: 72%
0.00721
Низкий

Дефекты

CWE-434

Связанные уязвимости

nvd
около 23 лет назад

The document management module in NOLA 1.1.1 and 1.1.2 does not restrict the types of files that are uploaded, which allows remote attackers to upload and execute arbitrary PHP files with extensions such as .php4.

EPSS

Процентиль: 72%
0.00721
Низкий

Дефекты

CWE-434