CVE-2017-18048
23.01.2018, 06:29
Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (lowercase) is blocked but .PHP (uppercase) is not.Enginsight
| Vendor | Product | Version |
|---|---|---|
| monstra | monstra | 3.0.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References