HIGH
Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension to a directory specified in the destination parameter, then accessing the uploaded file via a direct request, as demonstrated using workspace/masters/
Published Aug 11, 2008
8.5
HIGHCVSS 2.0
EPSS 6.81%
Description
Affected products
Remediation
Metrics
References (5)
Change history (0)
No recorded changes yet.