CVE-2018-16974
12.09.2018, 21:29
An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in apps/filemanager/upload/drop.php by using /filemanager/api/rm/.htaccess to remove the .htaccess file, and then using a filename that ends in .php followed by space characters (for bypassing the blacklist).Enginsight
Vendor | Product | Version |
---|---|---|
elefantcms | elefant | 𝑥 < 2.0.7 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References