Количество 4
Количество 4
CVE-2020-14209
Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht and .phar files can be uploaded. Also, a .htaccess file can be uploaded to reconfigure access control (e.g., to let .noexe files be executed as PHP code to defeat the .noexe protection mechanism).
CVE-2020-14209
Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht and .phar files can be uploaded. Also, a .htaccess file can be uploaded to reconfigure access control (e.g., to let .noexe files be executed as PHP code to defeat the .noexe protection mechanism).
CVE-2020-14209
Dolibarr before 11.0.5 allows low-privilege users to upload files of d ...
GHSA-2gcp-xwxg-hqg3
Dolibarr Unrestricted Upload of File with Dangerous Type
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2020-14209 Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht and .phar files can be uploaded. Also, a .htaccess file can be uploaded to reconfigure access control (e.g., to let .noexe files be executed as PHP code to defeat the .noexe protection mechanism). | CVSS3: 8.8 | 10% Низкий | больше 5 лет назад | |
CVE-2020-14209 Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht and .phar files can be uploaded. Also, a .htaccess file can be uploaded to reconfigure access control (e.g., to let .noexe files be executed as PHP code to defeat the .noexe protection mechanism). | CVSS3: 8.8 | 10% Низкий | больше 5 лет назад | |
CVE-2020-14209 Dolibarr before 11.0.5 allows low-privilege users to upload files of d ... | CVSS3: 8.8 | 10% Низкий | больше 5 лет назад | |
GHSA-2gcp-xwxg-hqg3 Dolibarr Unrestricted Upload of File with Dangerous Type | CVSS3: 8.8 | 10% Низкий | больше 3 лет назад |
Уязвимостей на страницу