CVE-2023-53942 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

File Thingie 2.5.7 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious PHP zip archives to the web server. Atta…
Critical CVSS: 9.4

CVE-2023-53942

File Thingie 2.5.7 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious PHP zip archives to the web server. Attackers can create a custom PHP payload, upload and unzip it, and then execute arbitrary system commands through a crafted PHP script with a command parameter.
Vendor
Leefish
Product
File Thingie
CWE
CWE-434
Yayın Tarihi
2025-12-18 20:15:52
Güncelleme
2025-12-31 17:22:07
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-

Kategoriler

Referanslar