CVE-2019-19745
17.12.2019, 15:15
Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute them on the server.Enginsight
Vendor | Product | Version |
---|---|---|
contao | contao | 4.4 ≤ 𝑥 ≤ 4.4.45 |
contao | contao | 4.8 ≤ 𝑥 ≤ 4.8.5 |
contao | contao | 4.0 |
contao | contao | 4.1 |
contao | contao | 4.2 |
contao | contao | 4.3 |
contao | contao | 4.5 |
contao | contao | 4.6 |
contao | contao | 4.7 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration