FileUploadsFilter.php in X2Engine 4.1.7 and earlier, when running on case-insensitive file systems, allows remote attackers to bypass the upload blacklist and conduct unrestricted file upload attacks by uploading a file with an executable extension that contains uppercase letters, as demonstrated using a PHP program.
References
Configurations
Information
Published : 2014-10-09 18:55
Updated : 2018-10-09 12:50
NVD link : CVE-2014-5298
Mitre link : CVE-2014-5298
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
x2engine
- x2engine