Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pg6w-hq9f-wfwr

Опубликовано: 26 дек. 2023
Источник: github
Github: Не прошло ревью

Описание

resumable.php (aka PHP backend for resumable.js) 0.1.4 before 3c6dbf5 allows arbitrary file upload anywhere in the filesystem via ../ in multipart/form-data content to upload.php. (File overwrite hasn't been possible with the code available in GitHub in recent years, however.)

resumable.php (aka PHP backend for resumable.js) 0.1.4 before 3c6dbf5 allows arbitrary file upload anywhere in the filesystem via ../ in multipart/form-data content to upload.php. (File overwrite hasn't been possible with the code available in GitHub in recent years, however.)

EPSS

Процентиль: 27%
0.00097
Низкий

Связанные уязвимости

CVSS3: 8.1
nvd
около 2 лет назад

resumable.php (aka PHP backend for resumable.js) 0.1.4 before 3c6dbf5 allows arbitrary file upload anywhere in the filesystem via ../ in multipart/form-data content to upload.php. (File overwrite hasn't been possible with the code available in GitHub in recent years, however.)

EPSS

Процентиль: 27%
0.00097
Низкий