Описание
Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page.
Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2023-37152
- https://github.com/Trinity-SYT-SECURITY/arbitrary-file-upload-RCE/blob/main/Online%20Art%20gallery%20project%201.0.md
- https://www.chtsecurity.com/news/ad3cee07-3e35-45c0-97f9-811cce13dda9
- https://www.chtsecurity.com/news/afe25fb4-55ac-45d9-9ece-cbc1edda2fb2%20
- https://www.exploit-db.com/exploits/51524
Связанные уязвимости
CVSS3: 9.8
nvd
больше 2 лет назад
Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page. Note: This has been disputed as not a valid vulnerability.