CVE-2018-12914
27.06.2018, 18:29
A remote code execution issue was discovered in PublicCMS V4.0.20180210. An attacker can upload a ZIP archive that contains a .jsp file with a directory traversal pathname. After an unzip operation, the attacker can execute arbitrary code by visiting a .jsp URI.Enginsight
Vendor | Product | Version |
---|---|---|
publiccms | publiccms | 4.0.20180210 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration