Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-12170

Опубликовано: 17 мая 2019
Источник: nvd
CVSS3: 8.8
CVSS2: 9
EPSS Средний

Описание

ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) component. This may result in remote command execution. An attacker can use the instructor account to fully compromise the system using a crafted backup ZIP archive. This will allow for PHP files to be written to the web root, and for code to execute on the remote server.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:atutor:atutor:*:*:*:*:*:*:*:*
Версия до 2.2.4 (включая)

EPSS

Процентиль: 94%
0.15293
Средний

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) component. This may result in remote command execution. An attacker can use the instructor account to fully compromise the system using a crafted backup ZIP archive. This will allow for PHP files to be written to the web root, and for code to execute on the remote server.

EPSS

Процентиль: 94%
0.15293
Средний

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-434