Security Advisory

CVE-2017-5520

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-01-17 09:22:00
Last updated 2024-08-05 15:04:14
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The media rename feature in GeniXCMS through 0.0.8 does not consider alternative PHP file extensions when checking uploaded files for PHP content, which enables a user to rename and execute files with the `.php6`, `.php7` and `.phtml` extensions.