Логотип exploitDog
bind:CVE-2018-17418
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-17418

Количество 2

Количество 2

nvd логотип

CVE-2018-17418

почти 7 лет назад

Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP filename, because plugins\box\filesmanager\filesmanager.admin.php mishandles the forbidden_types variable.

CVSS3: 7.2
EPSS: Средний
github логотип

GHSA-749q-p95g-24g2

больше 3 лет назад

Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP filename, because plugins\box\filesmanager\filesmanager.admin.php mishandles the forbidden_types variable.

CVSS3: 7.2
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-17418

Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP filename, because plugins\box\filesmanager\filesmanager.admin.php mishandles the forbidden_types variable.

CVSS3: 7.2
14%
Средний
почти 7 лет назад
github логотип
GHSA-749q-p95g-24g2

Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP filename, because plugins\box\filesmanager\filesmanager.admin.php mishandles the forbidden_types variable.

CVSS3: 7.2
14%
Средний
больше 3 лет назад

Уязвимостей на страницу