Описание
Sourcecodester Web-based Pharmacy Product Management System v.1.0 has a file upload vulnerability. An attacker can upload a PHP file disguised as an image by modifying the Content-Type header to image/jpg.
Ссылки
- ExploitThird Party Advisory
- Product
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:senior-walter:web-based_pharmacy_product_management_system:1.0:*:*:*:*:*:*:*
EPSS
Процентиль: 37%
0.00157
Низкий
8.6 High
CVSS3
Дефекты
CWE-434
Связанные уязвимости
CVSS3: 8.6
github
9 месяцев назад
Sourcecodester Web-based Pharmacy Product Management System v.1.0 has a file upload vulnerability. An attacker can upload a PHP file disguised as an image by modifying the Content-Type header to image/jpg.
EPSS
Процентиль: 37%
0.00157
Низкий
8.6 High
CVSS3
Дефекты
CWE-434