Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-5298

Опубликовано: 10 окт. 2014
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

FileUploadsFilter.php in X2Engine 4.1.7 and earlier, when running on case-insensitive file systems, allows remote attackers to bypass the upload blacklist and conduct unrestricted file upload attacks by uploading a file with an executable extension that contains uppercase letters, as demonstrated using a PHP program.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:x2engine:x2engine:*:*:*:*:*:*:*:*
Версия до 4.1.7 (включая)

EPSS

Процентиль: 79%
0.01227
Низкий

5 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
больше 3 лет назад

FileUploadsFilter.php in X2Engine 4.1.7 and earlier, when running on case-insensitive file systems, allows remote attackers to bypass the upload blacklist and conduct unrestricted file upload attacks by uploading a file with an executable extension that contains uppercase letters, as demonstrated using a PHP program.

EPSS

Процентиль: 79%
0.01227
Низкий

5 Medium

CVSS2

Дефекты

CWE-264