Security Advisory

CVE-2016-10756

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-05-24 17:41:16
Last updated 2024-08-06 03:30:20
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Kliqqi 3.0.0.5 allows CSRF with resultant Arbitrary File Upload because module.php?module=upload can be used to configure the uploading of .php files, and then modules/upload/upload_main.php can be used for the upload itself.