CVE-2011-2745
27.07.2011, 02:55
upload_handler.php in the swfupload extension in Chyrp 2.0 and earlier relies on client-side JavaScript code to restrict the file extensions of uploaded files, which allows remote authenticated users to upload a .php file, and consequently execute arbitrary PHP code, via a write_post action to the default URI under admin/.Enginsight
Vendor | Product | Version |
---|---|---|
chyrp | chyrp | 𝑥 ≤ 2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References