PT-2019-7548 · Serendipity · Serendipity

Publicado

2019-05-24

·

Atualizado

2019-05-29

·

CVE-2016-10752

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Serendipity version 2.0.3
Description The issue allows remote attackers to upload and execute arbitrary PHP code due to mishandling of an extensionless filename during a rename. This can be demonstrated by using "php" as a filename.
Recommendations For Serendipity version 2.0.3, consider disabling the serendipity moveMediaDirectory function until a patch is available to prevent the upload and execution of arbitrary PHP code.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-10752

Produtos afetados

Serendipity