CVE-2020-37073 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Victor CMS 1.0 contains an authenticated file upload vulnerability that allows administrators to upload PHP files with arbitrary content through the user_image…
High CVSS: 8.6

CVE-2020-37073

Victor CMS 1.0 contains an authenticated file upload vulnerability that allows administrators to upload PHP files with arbitrary content through the user_image parameter. Attackers can upload a malicious PHP shell to the /img/ directory and execute system commands by accessing the uploaded file with a 'cmd' parameter.
Vendor
Victor Cms Project
Product
Victor Cms
CWE
CWE-434
Yayın Tarihi
2026-02-03 22:16:22
Güncelleme
2026-02-10 14:52:48
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-

Kategoriler

Referanslar