Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-10557

Опубликовано: 16 мар. 2020
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

An issue was discovered in AContent through 1.4. It allows the user to run commands on the server with a low-privileged account. The upload section in the file manager page contains an arbitrary file upload vulnerability via upload.php. The extension .php7 bypasses file upload restrictions.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:atutor:acontent:*:*:*:*:*:*:*:*
Версия до 1.4 (включая)

EPSS

Процентиль: 35%
0.00146
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-434

Связанные уязвимости

github
больше 3 лет назад

An issue was discovered in AContent through 1.4. It allows the user to run commands on the server with a low-privileged account. The upload section in the file manager page contains an arbitrary file upload vulnerability via upload.php. The extension .php7 bypasses file upload restrictions.

EPSS

Процентиль: 35%
0.00146
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-434