Microweber 1.0.3 Shell Upload...

- AV AC AU C I A
发布: 2015-08-06
修订: 2025-04-13

Microweber version 1.0.3 suffers from an authenticated arbitrary command execution vulnerability. The issue is caused due to the improper verification when uploading files in '/src/Microweber/functions/plupload.php' script. This can be exploited to execute arbitrary PHP code by bypassing the extension restriction by putting the dot character at the end of the filename and uploading a malicious PHP script file that will be stored in '/userfiles/media/localhost/uploaded' directory.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息