Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-9492

Опубликовано: 13 июл. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to unrestricted upload of dangerous file types. In the generated form.lib.php file, upload file types are checked against a hard-coded list of dangerous extensions. This list does not include all variations of PHP files, which may lead to execution of the contained PHP code if the attacker can guess the uploaded filename. The form by default appends a short random string to the end of the filename.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jqueryform:php_formmail_generator:*:*:*:*:*:*:*:*
Версия до 2016-12-17 (исключая)

EPSS

Процентиль: 73%
0.00786
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-434
CWE-434

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to unrestricted upload of dangerous file types. In the generated form.lib.php file, upload file types are checked against a hard-coded list of dangerous extensions. This list does not include all variations of PHP files, which may lead to execution of the contained PHP code if the attacker can guess the uploaded filename. The form by default appends a short random string to the end of the filename.

EPSS

Процентиль: 73%
0.00786
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-434
CWE-434