Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-grf4-rjfm-p934

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Unrestricted file upload vulnerability in admin/upload_files.php in Zomplog 3.8.1 and earlier allows remote authenticated administrators to upload and execute arbitrary .php files by sending a modified MIME type. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2007-5230.

Unrestricted file upload vulnerability in admin/upload_files.php in Zomplog 3.8.1 and earlier allows remote authenticated administrators to upload and execute arbitrary .php files by sending a modified MIME type. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2007-5230.

EPSS

Процентиль: 89%
0.04327
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
больше 18 лет назад

Unrestricted file upload vulnerability in admin/upload_files.php in Zomplog 3.8.1 and earlier allows remote authenticated administrators to upload and execute arbitrary .php files by sending a modified MIME type. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2007-5230.

EPSS

Процентиль: 89%
0.04327
Низкий

Дефекты

CWE-20