CVE-2015-5457
08.07.2015, 15:59
PivotX before 2.3.11 does not validate the new file extension when renaming a file with multiple extensions, which allows remote attackers to execute arbitrary code by uploading a crafted file, as demonstrated by a file named foo.php.php.Enginsight
Vendor | Product | Version |
---|---|---|
pivotx | pivotx | 𝑥 ≤ 2.3.10 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References