Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m44j-mw65-mfmv

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Unspecified vulnerability in the XOOPS uploader class in Xoops 2.0.17.1-RC1 and earlier allows remote attackers to upload arbitrary files via unspecified vectors related to improper upload configuration settings in class/uploader.php and class/mimetypes.inc.php, possibly an incomplete blacklist that omits the .php4 extension.

Unspecified vulnerability in the XOOPS uploader class in Xoops 2.0.17.1-RC1 and earlier allows remote attackers to upload arbitrary files via unspecified vectors related to improper upload configuration settings in class/uploader.php and class/mimetypes.inc.php, possibly an incomplete blacklist that omits the .php4 extension.

EPSS

Процентиль: 79%
0.01242
Низкий

Связанные уязвимости

nvd
больше 18 лет назад

Unspecified vulnerability in the XOOPS uploader class in Xoops 2.0.17.1-RC1 and earlier allows remote attackers to upload arbitrary files via unspecified vectors related to improper upload configuration settings in class/uploader.php and class/mimetypes.inc.php, possibly an incomplete blacklist that omits the .php4 extension.

EPSS

Процентиль: 79%
0.01242
Низкий