CVE-2018-6383

CVE-2018-6383

Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phar extension, which allows remote authenticated admins to execute arbitrary PHP code by uploading a file, a different vulnerability than CVE-2017-18048.

Source: CVE-2018-6383

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다