Описание
ShopXO RCE Vulnerability
A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar where the suffix is JPG, which is uploaded after modifying the phar suffix.
Пакеты
Наименование
shopxo/shopxo
composer
Затронутые версииВерсия исправления
<= 1.9.3
Отсутствует
Связанные уязвимости
CVSS3: 9.8
nvd
больше 4 лет назад
A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar where the suffix is JPG, which is uploaded after modifying the phar suffix.