Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rr9c-438j-jfpx

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remote authenticated users to execute arbitrary PHP code via an uploaded .php file.

The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remote authenticated users to execute arbitrary PHP code via an uploaded .php file.

EPSS

Процентиль: 87%
0.03609
Низкий

Связанные уязвимости

nvd
больше 19 лет назад

The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remote authenticated users to execute arbitrary PHP code via an uploaded .php file.

EPSS

Процентиль: 87%
0.03609
Низкий