Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hg78-9p95-85mv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An Arbitrary File Upload in the Upload Image component in SourceCodester Car Rental Management System 1.0 allows the user to conduct remote code execution via admin/index.php?page=manage_car because .php files can be uploaded to admin/assets/uploads/ (under the web root).

An Arbitrary File Upload in the Upload Image component in SourceCodester Car Rental Management System 1.0 allows the user to conduct remote code execution via admin/index.php?page=manage_car because .php files can be uploaded to admin/assets/uploads/ (under the web root).

EPSS

Процентиль: 92%
0.07715
Низкий

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
больше 5 лет назад

An Arbitrary File Upload in the Upload Image component in SourceCodester Car Rental Management System 1.0 allows the user to conduct remote code execution via admin/index.php?page=manage_car because .php files can be uploaded to admin/assets/uploads/ (under the web root).

EPSS

Процентиль: 92%
0.07715
Низкий

Дефекты

CWE-434