Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h2r2-3pcg-323x

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote authenticated super-administrators to execute arbitrary code by uploading a theme file with an zip extension, and then accessing it via unspecified vectors.

Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote authenticated super-administrators to execute arbitrary code by uploading a theme file with an zip extension, and then accessing it via unspecified vectors.

EPSS

Процентиль: 75%
0.00875
Низкий

7.2 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.2
nvd
около 9 лет назад

Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote authenticated super-administrators to execute arbitrary code by uploading a theme file with an zip extension, and then accessing it via unspecified vectors.

CVSS3: 7.2
debian
около 9 лет назад

Unrestricted file upload vulnerability in the Blog appearance in the " ...

EPSS

Процентиль: 75%
0.00875
Низкий

7.2 High

CVSS3

Дефекты

CWE-434