PT-2016-7835 · Zikula · Zikula
Xyntax
·
Publicado
2016-12-05
·
Atualizado
2016-12-27
·
CVE-2016-9835
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zikula versions 1.3.x through 1.3.10
Zikula versions 1.4.x through 1.4.3
Description
A directory traversal issue in the file "jcss.php" allows a remote attacker to launch a PHP object injection by uploading a serialized file.
Recommendations
For Zikula versions 1.3.x through 1.3.10, update to version 1.3.11 or later.
For Zikula versions 1.4.x through 1.4.3, update to version 1.4.4 or later.
Correção
Command Injection
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Zikula