Логотип exploitDog
bind:CVE-2021-43617
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-43617

Количество 5

Количество 5

ubuntu логотип

CVE-2021-43617

больше 3 лет назад

Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for .phar files, which are handled as application/x-httpd-php on systems based on Debian. NOTE: this CVE Record is for Laravel Framework, and is unrelated to any reports concerning incorrectly written user applications for image upload.

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2021-43617

больше 3 лет назад

Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for .phar files, which are handled as application/x-httpd-php on systems based on Debian. NOTE: this CVE Record is for Laravel Framework, and is unrelated to any reports concerning incorrectly written user applications for image upload.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2021-43617

больше 3 лет назад

Laravel Framework through 8.70.2 does not sufficiently block the uploa ...

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-364w-9g92-3grq

больше 3 лет назад

Withdrawn: Laravel Framework does not sufficiently block the upload of executable PHP content.

EPSS: Средний
fstec логотип

BDU:2021-06021

больше 3 лет назад

Уязвимость PHP-фреймворка Laravel, связанная с неограниченной загрузкой файлов опасного типа, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-43617

Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for .phar files, which are handled as application/x-httpd-php on systems based on Debian. NOTE: this CVE Record is for Laravel Framework, and is unrelated to any reports concerning incorrectly written user applications for image upload.

CVSS3: 9.8
48%
Средний
больше 3 лет назад
nvd логотип
CVE-2021-43617

Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for .phar files, which are handled as application/x-httpd-php on systems based on Debian. NOTE: this CVE Record is for Laravel Framework, and is unrelated to any reports concerning incorrectly written user applications for image upload.

CVSS3: 9.8
48%
Средний
больше 3 лет назад
debian логотип
CVE-2021-43617

Laravel Framework through 8.70.2 does not sufficiently block the uploa ...

CVSS3: 9.8
48%
Средний
больше 3 лет назад
github логотип
GHSA-364w-9g92-3grq

Withdrawn: Laravel Framework does not sufficiently block the upload of executable PHP content.

48%
Средний
больше 3 лет назад
fstec логотип
BDU:2021-06021

Уязвимость PHP-фреймворка Laravel, связанная с неограниченной загрузкой файлов опасного типа, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
48%
Средний
больше 3 лет назад

Уязвимостей на страницу