Логотип exploitDog
bind:CVE-2018-20127
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-20127

Количество 2

Количество 2

nvd логотип

CVE-2018-20127

около 7 лет назад

An issue was discovered in zzzphp cms 1.5.8. del_file in /admin/save.php allows remote attackers to delete arbitrary files via a mixed-case extension and an extra '.' character, because (for example) "php" is blocked but path=F:/1.phP. succeeds.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-9gcf-rjxj-c7gp

больше 3 лет назад

An issue was discovered in zzzphp cms 1.5.8. del_file in /admin/save.php allows remote attackers to delete arbitrary files via a mixed-case extension and an extra '.' character, because (for example) "php" is blocked but path=F:/1.phP. succeeds.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-20127

An issue was discovered in zzzphp cms 1.5.8. del_file in /admin/save.php allows remote attackers to delete arbitrary files via a mixed-case extension and an extra '.' character, because (for example) "php" is blocked but path=F:/1.phP. succeeds.

CVSS3: 7.5
1%
Низкий
около 7 лет назад
github логотип
GHSA-9gcf-rjxj-c7gp

An issue was discovered in zzzphp cms 1.5.8. del_file in /admin/save.php allows remote attackers to delete arbitrary files via a mixed-case extension and an extra '.' character, because (for example) "php" is blocked but path=F:/1.phP. succeeds.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу