Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vg4r-rg5m-fvpf

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Discuz! 4.0 rc4 does not properly restrict types of files that are uploaded to the server, which allows remote attackers to execute arbitrary commands via a filename containing ".php.rar" or other multiple extensions that include .php.

Discuz! 4.0 rc4 does not properly restrict types of files that are uploaded to the server, which allows remote attackers to execute arbitrary commands via a filename containing ".php.rar" or other multiple extensions that include .php.

EPSS

Процентиль: 82%
0.02296
Низкий

Связанные уязвимости

nvd
почти 21 год назад

Discuz! 4.0 rc4 does not properly restrict types of files that are uploaded to the server, which allows remote attackers to execute arbitrary commands via a filename containing ".php.rar" or other multiple extensions that include .php.

EPSS

Процентиль: 82%
0.02296
Низкий