CVE-2014-0342

Multiple unrestricted file upload vulnerabilities in fileupload.php in PivotX before 2.3.9 allow remote authenticated users to execute arbitrary PHP code by uploading a file with a (1) .php or (2) .php# extension, and then accessing it via unspecified vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
certccCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 67%
VendorProductVersion
pivotxpivotx
𝑥
≤ 2.3.8
pivotxpivotx
2.1.0
pivotxpivotx
2.1.1
pivotxpivotx
2.1.2
pivotxpivotx
2.2.0
pivotxpivotx
2.2.0:b1
pivotxpivotx
2.2.0:b2
pivotxpivotx
2.2.0:rc
pivotxpivotx
2.2.1
pivotxpivotx
2.2.2
pivotxpivotx
2.2.3
pivotxpivotx
2.2.5
pivotxpivotx
2.3.0
pivotxpivotx
2.3.2
pivotxpivotx
2.3.3
pivotxpivotx
2.3.5
pivotxpivotx
2.3.6
pivotxpivotx
2.3.7
𝑥
= Vulnerable software versions