Логотип exploitDog
bind:CVE-2020-35709
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-35709

Количество 2

Количество 2

nvd логотип

CVE-2020-35709

около 5 лет назад

bloofoxCMS 0.5.2.1 allows admins to upload arbitrary .php files (with "Content-Type: application/octet-stream") to ../media/images/ via the admin/index.php?mode=tools&page=upload URI, aka directory traversal.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-9c3c-p8mj-7wvw

больше 3 лет назад

bloofoxCMS 0.5.2.1 allows admins to upload arbitrary .php files (with "Content-Type: application/octet-stream") to ../media/images/ via the admin/index.php?mode=tools&page=upload URI, aka directory traversal.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-35709

bloofoxCMS 0.5.2.1 allows admins to upload arbitrary .php files (with "Content-Type: application/octet-stream") to ../media/images/ via the admin/index.php?mode=tools&page=upload URI, aka directory traversal.

CVSS3: 4.9
1%
Низкий
около 5 лет назад
github логотип
GHSA-9c3c-p8mj-7wvw

bloofoxCMS 0.5.2.1 allows admins to upload arbitrary .php files (with "Content-Type: application/octet-stream") to ../media/images/ via the admin/index.php?mode=tools&page=upload URI, aka directory traversal.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу