Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v77f-72jf-vjg9

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the upload parameter to images.php.

ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the upload parameter to images.php.

EPSS

Процентиль: 96%
0.21867
Средний

Дефекты

CWE-434

Связанные уязвимости

nvd
около 21 года назад

ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the upload parameter to images.php.

EPSS

Процентиль: 96%
0.21867
Средний

Дефекты

CWE-434