CVE-2018-20166

CVE-2018-20166

A file-upload vulnerability exists in Rukovoditel 2.3.1. index.php?module=configuration/save allows the user to upload a background image, and mishandles extension checking. It accepts uploads of PHP content if the first few characters match GIF data, and the filename ends in ".php" with mixed case, such as the .pHp extension.

Source: CVE-2018-20166

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다