PT-2016-7835 · Zikula · Zikula

Xyntax

·

Publicado

2016-12-05

·

Atualizado

2016-12-27

·

CVE-2016-9835

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zikula versions 1.3.x through 1.3.10 Zikula versions 1.4.x through 1.4.3
Description A directory traversal issue in the file "jcss.php" allows a remote attacker to launch a PHP object injection by uploading a serialized file.
Recommendations For Zikula versions 1.3.x through 1.3.10, update to version 1.3.11 or later. For Zikula versions 1.4.x through 1.4.3, update to version 1.4.4 or later.

Correção

Command Injection

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-9835

Produtos afetados

Zikula