Логотип exploitDog
bind:CVE-2021-24347
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24347

Количество 2

Количество 2

nvd логотип

CVE-2021-24347

больше 4 лет назад

The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that php files could still be uploaded by changing the file extension's case, for example, from "php" to "pHP".

CVSS3: 8.8
EPSS: Высокий
github логотип

GHSA-p8xc-86cg-8cgm

больше 3 лет назад

The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that php files could still be uploaded by changing the file extension's case, for example, from "php" to "pHP".

CVSS3: 8.8
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24347

The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that php files could still be uploaded by changing the file extension's case, for example, from "php" to "pHP".

CVSS3: 8.8
83%
Высокий
больше 4 лет назад
github логотип
GHSA-p8xc-86cg-8cgm

The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that php files could still be uploaded by changing the file extension's case, for example, from "php" to "pHP".

CVSS3: 8.8
83%
Высокий
больше 3 лет назад

Уязвимостей на страницу