CVE-2018-10574
30.04.2018, 20:29
site/index.php/admin/trees/add/ in BigTree 4.2.22 and earlier allows remote attackers to upload and execute arbitrary PHP code because the BigTreeStorage class in core/inc/bigtree/apis/storage.php does not prevent uploads of .htaccess files.
Vendor | Product | Version |
---|---|---|
bigtreecms | bigtree_cms | 𝑥 ≤ 4.2.22 |
𝑥
= Vulnerable software versions