PT-2019-7548 · Serendipity · Serendipity
Publicado
2019-05-24
·
Atualizado
2019-05-29
·
CVE-2016-10752
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Serendipity version 2.0.3
Description
The issue allows remote attackers to upload and execute arbitrary PHP code due to mishandling of an extensionless filename during a rename. This can be demonstrated by using "php" as a filename.
Recommendations
For Serendipity version 2.0.3, consider disabling the
serendipity moveMediaDirectory function until a patch is available to prevent the upload and execution of arbitrary PHP code.Correção
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Serendipity