Описание
DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploading files with double extensions via the fileupload parameter in a newthread action in newpost.php.
Ссылки
- Broken LinkExploit
- Broken LinkExploit
- Broken LinkPatchVendor Advisory
- ExploitThird Party Advisory
- Broken Link
- Third Party AdvisoryVDB Entry
- Broken LinkExploit
- Broken LinkExploit
- Broken LinkPatchVendor Advisory
- ExploitThird Party Advisory
- Broken Link
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 1.06 (включая)
cpe:2.3:a:deluxebb:deluxebb:*:*:*:*:*:*:*:*
EPSS
Процентиль: 92%
0.09018
Низкий
7.5 High
CVSS2
Дефекты
CWE-434
Связанные уязвимости
github
почти 4 года назад
DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploading files with double extensions via the fileupload parameter in a newthread action in newpost.php.
EPSS
Процентиль: 92%
0.09018
Низкий
7.5 High
CVSS2
Дефекты
CWE-434