Security Advisory

CVE-2018-18874

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-10-31 16:00:00
Last updated 2024-09-16 17:18:25
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

nc-cms through 2017-03-10 allows remote attackers to execute arbitrary PHP code via the "Upload File or Image" feature, with a .php filename and "Content-Type: application/octet-stream" to the index.php?action=file_manager_upload URI.