Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jm8f-hx2x-mfjv

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Unrestricted file upload vulnerability in The Address Book 1.04e validates the Content-Type header but not the file extension, which allows remote attackers to upload arbitrary PHP scripts.

Unrestricted file upload vulnerability in The Address Book 1.04e validates the Content-Type header but not the file extension, which allows remote attackers to upload arbitrary PHP scripts.

EPSS

Процентиль: 66%
0.00524
Низкий

Связанные уязвимости

nvd
около 19 лет назад

Unrestricted file upload vulnerability in The Address Book 1.04e validates the Content-Type header but not the file extension, which allows remote attackers to upload arbitrary PHP scripts.

EPSS

Процентиль: 66%
0.00524
Низкий