Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jpq9-fcx6-h2p8

Опубликовано: 09 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter in some realistic web-server configurations.)

Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter in some realistic web-server configurations.)

EPSS

Процентиль: 92%
0.09022
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
около 3 лет назад

Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter in some realistic web-server configurations.)

EPSS

Процентиль: 92%
0.09022
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434