Количество 2
Количество 2
CVE-2018-3814
около 8 лет назад
Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and then the "Replace it" option, because this allows a .jpg file to have embedded PHP code, and then be renamed to a .php extension.
CVSS3: 8.8
EPSS: Низкий
GHSA-r342-vjc4-wrmj
больше 3 лет назад
Craft CMS PHP Code Injection Vulnerability
CVSS3: 8.8
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2018-3814 Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and then the "Replace it" option, because this allows a .jpg file to have embedded PHP code, and then be renamed to a .php extension. | CVSS3: 8.8 | 1% Низкий | около 8 лет назад | |
GHSA-r342-vjc4-wrmj Craft CMS PHP Code Injection Vulnerability | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу
20