Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-2270

Опубликовано: 01 июл. 2009
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

Unrestricted file upload vulnerability in member/uploads_edit.php in dedecms 5.3 allows remote attackers to execute arbitrary code by uploading a file with a double extension in the filename, then accessing this file via unspecified vectors, as demonstrated by a .jpg.php filename.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dedecms:dedecms:5.3:*:*:*:*:*:*:*

EPSS

Процентиль: 77%
0.01053
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-94

Связанные уязвимости

github
почти 4 года назад

Unrestricted file upload vulnerability in member/uploads_edit.php in dedecms 5.3 allows remote attackers to execute arbitrary code by uploading a file with a double extension in the filename, then accessing this file via unspecified vectors, as demonstrated by a .jpg.php filename.

EPSS

Процентиль: 77%
0.01053
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-94