Логотип exploitDog
bind:CVE-2017-11756
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-11756

Количество 2

Количество 2

nvd логотип

CVE-2017-11756

больше 8 лет назад

In Earcms Ear Music through 4.1 build 20170710, remote authenticated users can execute arbitrary PHP code by changing the allowable music-upload extensions to include .php in addition to .mp3 and .m4a in admin.php?iframe=config_upload, and then using user.php/music/add/ to upload the code.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-wc6j-4h3g-8crj

больше 3 лет назад

In Earcms Ear Music through 4.1 build 20170710, remote authenticated users can execute arbitrary PHP code by changing the allowable music-upload extensions to include .php in addition to .mp3 and .m4a in admin.php?iframe=config_upload, and then using user.php/music/add/ to upload the code.

CVSS3: 7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-11756

In Earcms Ear Music through 4.1 build 20170710, remote authenticated users can execute arbitrary PHP code by changing the allowable music-upload extensions to include .php in addition to .mp3 and .m4a in admin.php?iframe=config_upload, and then using user.php/music/add/ to upload the code.

CVSS3: 7
0%
Низкий
больше 8 лет назад
github логотип
GHSA-wc6j-4h3g-8crj

In Earcms Ear Music through 4.1 build 20170710, remote authenticated users can execute arbitrary PHP code by changing the allowable music-upload extensions to include .php in addition to .mp3 and .m4a in admin.php?iframe=config_upload, and then using user.php/music/add/ to upload the code.

CVSS3: 7
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу