CVE-2017-7625
10.04.2017, 17:59
In Fiyo CMS 2.x through 2.0.7, attackers may upload a webshell via the content parameter to "/dapur/apps/app_theme/libs/save_file.php" and then execute code.
Vendor | Product | Version |
---|---|---|
fiyo | fiyo_cms | 2.0 |
fiyo | fiyo_cms | 2.0.1.6 |
fiyo | fiyo_cms | 2.0.1.8 |
fiyo | fiyo_cms | 2.0.2.1 |
fiyo | fiyo_cms | 2.0.6 |
fiyo | fiyo_cms | 2.0.7 |
𝑥
= Vulnerable software versions