CVE-2019-17490
10.10.2019, 21:15
app\modules\polygon\controllers\ProblemController in Jiangnan Online Judge (aka jnoj) 0.8.0 allows arbitrary file upload, as demonstrated by PHP code (with a .php filename but the image/png content type) to the web/polygon/problem/tests URI.Enginsight
Vendor | Product | Version |
---|---|---|
jnoj | jiangnan_online_judge | 0.8.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration