Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (lowercase) is blocked but .PHP (uppercase) is not.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-01-23T06:00:00

Updated: 2024-08-05T21:06:50.128Z

Reserved: 2018-01-22T00:00:00

Link: CVE-2017-18048

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-01-23T06:29:00.213

Modified: 2018-02-08T16:28:31.783

Link: CVE-2017-18048

cve-icon Redhat

No data.