HIGH
Unrestricted file upload vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly AjaXplorer) before 5.0.4 allows remote attackers to execute arbitrary code by uploading an executable file, and then accessing this file at a location specified by the format parameter of a move operation
Published Dec 27, 2014
7.5
HIGHCVSS 2.0
EPSS 7.96%
Description
Affected products
Remediation
References (3)
Change history (0)
No recorded changes yet.