CVE-2017-18048
EUVD-2017-918823.01.2018, 06:29
Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (lowercase) is blocked but .PHP (uppercase) is not.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| monstra | monstra | 3.0.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References