Логотип exploitDog
bind:CVE-2011-2745
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2011-2745

Количество 2

Количество 2

nvd логотип

CVE-2011-2745

больше 14 лет назад

upload_handler.php in the swfupload extension in Chyrp 2.0 and earlier relies on client-side JavaScript code to restrict the file extensions of uploaded files, which allows remote authenticated users to upload a .php file, and consequently execute arbitrary PHP code, via a write_post action to the default URI under admin/.

CVSS2: 6.5
EPSS: Низкий
github логотип

GHSA-rq7c-vpq5-hm7w

больше 3 лет назад

upload_handler.php in the swfupload extension in Chyrp 2.0 and earlier relies on client-side JavaScript code to restrict the file extensions of uploaded files, which allows remote authenticated users to upload a .php file, and consequently execute arbitrary PHP code, via a write_post action to the default URI under admin/.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2011-2745

upload_handler.php in the swfupload extension in Chyrp 2.0 and earlier relies on client-side JavaScript code to restrict the file extensions of uploaded files, which allows remote authenticated users to upload a .php file, and consequently execute arbitrary PHP code, via a write_post action to the default URI under admin/.

CVSS2: 6.5
2%
Низкий
больше 14 лет назад
github логотип
GHSA-rq7c-vpq5-hm7w

upload_handler.php in the swfupload extension in Chyrp 2.0 and earlier relies on client-side JavaScript code to restrict the file extensions of uploaded files, which allows remote authenticated users to upload a .php file, and consequently execute arbitrary PHP code, via a write_post action to the default URI under admin/.

2%
Низкий
больше 3 лет назад

Уязвимостей на страницу