ZeroHour

CVE-2017-18048

PoC ×3
CVSS 3.0
8.8 high
EPSS
63%p99
Published
()
Modified
Description

Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (lowercase) is blocked but .PHP (uppercase) is not.

Vendors
monstra
Products
monstra
Weakness
CWE-434
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.