Логотип exploitDog
bind:CVE-2020-37023
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-37023

Количество 2

Количество 2

nvd логотип

CVE-2020-37023

10 дней назад

Koken CMS 0.22.24 contains a file upload vulnerability that allows authenticated attackers to bypass file extension restrictions by renaming malicious PHP files. Attackers can upload PHP files with system command execution capabilities by manipulating the file upload request through a web proxy and changing the file extension.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-jfgg-fv6q-274f

10 дней назад

Koken CMS 0.22.24 contains a file upload vulnerability that allows authenticated attackers to bypass file extension restrictions by renaming malicious PHP files. Attackers can upload PHP files with system command execution capabilities by manipulating the file upload request through a web proxy and changing the file extension.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-37023

Koken CMS 0.22.24 contains a file upload vulnerability that allows authenticated attackers to bypass file extension restrictions by renaming malicious PHP files. Attackers can upload PHP files with system command execution capabilities by manipulating the file upload request through a web proxy and changing the file extension.

CVSS3: 8.8
0%
Низкий
10 дней назад
github логотип
GHSA-jfgg-fv6q-274f

Koken CMS 0.22.24 contains a file upload vulnerability that allows authenticated attackers to bypass file extension restrictions by renaming malicious PHP files. Attackers can upload PHP files with system command execution capabilities by manipulating the file upload request through a web proxy and changing the file extension.

CVSS3: 8.8
0%
Низкий
10 дней назад

Уязвимостей на страницу