Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-9493

Опубликовано: 13 июл. 2018
Источник: nvd
CVSS3: 6.1
CVSS2: 4.3
EPSS Низкий

Описание

The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to stored cross-site scripting. In the generated form.lib.php file, upload file types are checked against a hard-coded list of dangerous extensions. This list does not include all variations of PHP files, which may lead to execution of the contained PHP code if the attacker can guess the uploaded filename. The form by default appends a short random string to the end of the filename.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jqueryform:php_formmail_generator:*:*:*:*:*:*:*:*
Версия до 2016-12-17 (исключая)

EPSS

Процентиль: 43%
0.0021
Низкий

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-80
CWE-79

Связанные уязвимости

CVSS3: 6.1
github
больше 3 лет назад

The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to stored cross-site scripting. In the generated form.lib.php file, upload file types are checked against a hard-coded list of dangerous extensions. This list does not include all variations of PHP files, which may lead to execution of the contained PHP code if the attacker can guess the uploaded filename. The form by default appends a short random string to the end of the filename.

EPSS

Процентиль: 43%
0.0021
Низкий

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-80
CWE-79