Описание
Unrestricted file upload vulnerability in TomatoCMS 2.0.6 and earlier allows remote authenticated users, with certain privileges, to execute arbitrary PHP code by uploading an image file, and then accessing it via a direct request to the file in an unspecified directory.
Ссылки
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.0.6 (включая)
Одно из
cpe:2.3:a:tomatocms:tomatocms:*:*:*:*:*:*:*:*
cpe:2.3:a:tomatocms:tomatocms:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:tomatocms:tomatocms:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:tomatocms:tomatocms:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:tomatocms:tomatocms:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:tomatocms:tomatocms:2.0.3.1430:*:*:*:*:*:*:*
cpe:2.3:a:tomatocms:tomatocms:2.0.3.1622:*:*:*:*:*:*:*
cpe:2.3:a:tomatocms:tomatocms:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:tomatocms:tomatocms:2.0.5:*:*:*:*:*:*:*
EPSS
Процентиль: 64%
0.00466
Низкий
6 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
больше 3 лет назад
Unrestricted file upload vulnerability in TomatoCMS 2.0.6 and earlier allows remote authenticated users, with certain privileges, to execute arbitrary PHP code by uploading an image file, and then accessing it via a direct request to the file in an unspecified directory.
EPSS
Процентиль: 64%
0.00466
Низкий
6 Medium
CVSS2
Дефекты
NVD-CWE-Other