Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product preview" action, which can make a .php file accessible under a uploads/ URI.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.exploit-db.com/exploits/43315/ |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-12-24T00:00:00
Updated: 2024-08-05T21:06:49.041Z
Reserved: 2017-12-23T00:00:00
Link: CVE-2017-17874
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-12-27T17:08:20.953
Modified: 2024-11-21T03:18:52.130
Link: CVE-2017-17874
Redhat
No data.