CVE-2020-36485

Portable Ltd Playable v9.18 was discovered to contain an arbitrary file upload vulnerability in the filename parameter of the upload module. This vulnerability allows attackers to execute arbitrary code via a crafted JPEG file.
References
Link Resource
https://www.vulnerability-lab.com/get_content.php?id=2198 Exploit Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:madeportable:playable:9.18:*:*:*:*:iphone_os:*:*

Information

Published : 2021-10-22 13:15

Updated : 2021-10-28 10:06


NVD link : CVE-2020-36485

Mitre link : CVE-2020-36485


JSON object : View

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type

Advertisement

dedicated server usa

Products Affected

madeportable

  • playable