PT-2019-15875 · Php · Class.Upload.Php

Jra89

·

Publicado

2019-12-04

·

Atualizado

2020-01-16

·

CVE-2019-19576

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions class.upload.php versions prior to 1.0.3 class.upload.php versions 2.x prior to 2.0.4
Description The issue is related to the omission of .phar from the set of dangerous file extensions in class.upload.php, which can be exploited for remote code execution.
Recommendations For versions prior to 1.0.3, update to version 1.0.3 or later. For versions 2.x prior to 2.0.4, update to version 2.0.4 or later.

Exploit

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-19576
GHSA-R5GM-4P5W-PQ2P

Produtos afetados

Class.Upload.Php