ZeroHour

CVE-2017-5520

PoC
CVSS 3.0
8.8 high
EPSS
2%p77
Published
()
Modified
Description

The media rename feature in GeniXCMS through 0.0.8 does not consider alternative PHP file extensions when checking uploaded files for PHP content, which enables a user to rename and execute files with the `.php6`, `.php7` and `.phtml` extensions.

Vendors
metalgenix
Products
genixcms
Weakness
CWE-434
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.