CVE-2017-18048

Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (lowercase) is blocked but .PHP (uppercase) is not.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:monstra:monstra:3.0.4:*:*:*:*:*:*:*

Information

Published : 2018-01-22 22:29

Updated : 2018-02-08 08:28


NVD link : CVE-2017-18048

Mitre link : CVE-2017-18048


JSON object : View

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type

Advertisement

dedicated server usa

Products Affected

monstra

  • monstra