Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fx5c-4j3x-4pc6

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploading files with double extensions via the fileupload parameter in a newthread action in newpost.php.

DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploading files with double extensions via the fileupload parameter in a newthread action in newpost.php.

EPSS

Процентиль: 92%
0.09018
Низкий

Дефекты

CWE-434

Связанные уязвимости

nvd
больше 19 лет назад

DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploading files with double extensions via the fileupload parameter in a newthread action in newpost.php.

EPSS

Процентиль: 92%
0.09018
Низкий

Дефекты

CWE-434