Svi
Pretraži prema proizvođaču
Pretraži prema CWE oznaci
O usluzi
Pretplate
Jezik
hr
en
CVE-2019-19576 - CERT CVE
CVE-2019-19576
ID
CVE-2019-19576
Sažetak
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.
Reference
https://github.com/verot/class.upload.php/compare/1.0.2...1.0.3
https://github.com/getk2/k2/commit/d1344706c4b74c2ae7659b286b5a066117155124
https://www.verot.net/php_class_upload.htm
https://github.com/verot/class.upload.php/commit/db1b4fe50c1754696970d8b437f07e7b94a7ebf2
https://github.com/verot/class.upload.php/compare/2.0.3...2.0.4
https://github.com/verot/class.upload.php/commit/5a7505ddec956fdc9e9c071ae5089865559174f1
https://www.verot.net
https://github.com/jra89/CVE-2019-19576
http://packetstormsecurity.com/files/155577/Verot-2.0.3-Remote-Code-Execution.html
https://medium.com/%40jra8908/cve-2019-19576-e9da712b779
CVSS
Base:
7.5
Impact:
6.4
Exploitability:
10.0
Pristup
Vektor
Složenost
Autentikacija
NETWORK
LOW
NONE
Impact
Povjerljivost
Cjelovitost
Dostupnost
PARTIAL
PARTIAL
PARTIAL
CVSS vektor
AV:N/AC:L/Au:N/C:P/I:P/A:P
Zadnje važnije ažuriranje
07-11-2023 - 03:07
Objavljeno
04-12-2019 - 18:15