ZeroHour

CVE-2016-10751

CVSS 3.0
7.2 high
EPSS
3%p86
Published
()
Modified
Description

osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote PHP code execution because an administrator can upload an image that contains PHP code in the EXIF data via index.php?page=ajax&action=ajax_upload.

Vendors
osclass
Products
osclass
Weakness
CWE-22, CWE-434
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.