Description
An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in apps/filemanager/upload/drop.php by using /filemanager/api/rm/.htaccess to remove the .htaccess file, and then using a filename that ends in .php followed by space characters (for bypassing the blacklist).
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2942 | An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in apps/filemanager/upload/drop.php by using /filemanager/api/rm/.htaccess to remove the .htaccess file, and then using a filename that ends in .php followed by space characters (for bypassing the blacklist). |
Github GHSA |
GHSA-77j2-7whr-6vpx | Elefant CMS Code Execution Vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T10:39:59.468Z
Reserved: 2018-09-12T00:00:00.000Z
Link: CVE-2018-16974
No data.
Status : Modified
Published: 2018-09-12T21:29:00.613
Modified: 2024-11-21T03:53:37.520
Link: CVE-2018-16974
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA