Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cfxx-rjmh-m6qv

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension to a directory specified in the destination parameter, then accessing the uploaded file via a direct request, as demonstrated using workspace/masters/.

Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension to a directory specified in the destination parameter, then accessing the uploaded file via a direct request, as demonstrated using workspace/masters/.

EPSS

Процентиль: 91%
0.0609
Низкий

Дефекты

CWE-94

Связанные уязвимости

nvd
больше 17 лет назад

Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension to a directory specified in the destination parameter, then accessing the uploaded file via a direct request, as demonstrated using workspace/masters/.

EPSS

Процентиль: 91%
0.0609
Низкий

Дефекты

CWE-94