Описание
ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the upload parameter to images.php.
Ссылки
- Broken LinkPatch
- Broken LinkVendor Advisory
- Broken LinkExploitThird Party AdvisoryVDB Entry
- Broken Link
- Broken LinkThird Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Broken LinkPatch
- Broken LinkVendor Advisory
- Broken LinkExploitThird Party AdvisoryVDB Entry
- Broken Link
- Broken LinkThird Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 0.617 (исключая)
cpe:2.3:a:e107:e107:*:*:*:*:*:*:*:*
EPSS
Процентиль: 96%
0.21867
Средний
7.5 High
CVSS2
Дефекты
CWE-434
Связанные уязвимости
github
почти 4 года назад
ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the upload parameter to images.php.
EPSS
Процентиль: 96%
0.21867
Средний
7.5 High
CVSS2
Дефекты
CWE-434