Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-13981

Опубликовано: 16 июл. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Средний

Описание

The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated remote code execution due to a default component that permits arbitrary upload of PHP files, because the formmailer widget blocks .php files but not .php5 or .phtml files. This is related to /assets/php/formmailer/SendEmail.php and /assets/php/formmailer/functions.php.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zeta-producer:zeta_producer_desktop_cms:*:*:*:*:*:*:*:*
Версия до 14.2.1 (исключая)

EPSS

Процентиль: 97%
0.36699
Средний

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated remote code execution due to a default component that permits arbitrary upload of PHP files, because the formmailer widget blocks .php files but not .php5 or .phtml files. This is related to /assets/php/formmailer/SendEmail.php and /assets/php/formmailer/functions.php.

EPSS

Процентиль: 97%
0.36699
Средний

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-434