CVE-2019-9825

FeiFeiCMS 4.1.190209 allows remote attackers to upload and execute arbitrary PHP code by visiting index.php?s=Admin-Index to modify the set of allowable file extensions, as demonstrated by adding php to the default jpg,gif,png,jpeg setting, and then using the "add article" feature.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:feifeicms:feifeicms:4.1.190209:*:*:*:*:*:*:*

Information

Published : 2019-03-14 15:29

Updated : 2019-03-19 07:11


NVD link : CVE-2019-9825

Mitre link : CVE-2019-9825


JSON object : View

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type

Advertisement

dedicated server usa

Products Affected

feifeicms

  • feifeicms