CVE-2016-9835
05.12.2016, 08:59
Directory traversal vulnerability in file "jcss.php" in Zikula 1.3.x before 1.3.11 and 1.4.x before 1.4.4 on Windows allows a remote attacker to launch a PHP object injection by uploading a serialized file.
Vendor | Product | Version |
---|---|---|
zikula | zikula_application_framework | 1.3.0 |
zikula | zikula_application_framework | 1.3.1 |
zikula | zikula_application_framework | 1.3.2 |
zikula | zikula_application_framework | 1.3.3 |
zikula | zikula_application_framework | 1.3.4 |
zikula | zikula_application_framework | 1.3.5 |
zikula | zikula_application_framework | 1.3.6 |
zikula | zikula_application_framework | 1.3.7 |
zikula | zikula_application_framework | 1.3.8 |
zikula | zikula_application_framework | 1.3.9 |
zikula | zikula_application_framework | 1.3.10 |
zikula | zikula_application_framework | 1.3.10:rc1 |
zikula | zikula_application_framework | 1.4.0 |
zikula | zikula_application_framework | 1.4.0:rc1 |
zikula | zikula_application_framework | 1.4.0:rc2 |
zikula | zikula_application_framework | 1.4.0:rc3 |
zikula | zikula_application_framework | 1.4.0:rc4 |
zikula | zikula_application_framework | 1.4.0:rc5 |
zikula | zikula_application_framework | 1.4.1 |
zikula | zikula_application_framework | 1.4.2 |
zikula | zikula_application_framework | 1.4.3 |
zikula | zikula_application_framework | 1.4.3:rc1 |
zikula | zikula_application_framework | 1.4.3:rc2 |
zikula | zikula_application_framework | 1.4.3:rc3 |
𝑥
= Vulnerable software versions
References