Beveiligingsadvies

CVE-2018-20166

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2019-01-02 18:00:00
Laatst bijgewerkt 2024-08-05 11:51:19
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

A file-upload vulnerability exists in Rukovoditel 2.3.1. index.php?module=configuration/save allows the user to upload a background image, and mishandles extension checking. It accepts uploads of PHP content if the first few characters match GIF data, and the filename ends in ".php" with mixed case, such as the .pHp extension.