HIGH
Unrestricted file upload vulnerability in the file_upload function in core/misc.class.php in EncapsGallery 2.0.2 allows remote authenticated administrators to upload and execute arbitrary PHP files by uploading a file with an executable extension, then accessing it via a direct request to the file in the rwx_gallery directory
Published Apr 27, 2008
9.0
HIGHCVSS 2.0
EPSS 2.58%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.