Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jg2m-4r5v-h2j3

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary .php filename in the zip parameter, which is created under sptemplates/.

Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary .php filename in the zip parameter, which is created under sptemplates/.

EPSS

Процентиль: 85%
0.02618
Низкий

Связанные уязвимости

nvd
больше 18 лет назад

Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary .php filename in the zip parameter, which is created under sptemplates/.

EPSS

Процентиль: 85%
0.02618
Низкий