CVE-2011-1329 Information
Feb 14, 2021
cve
Description
WalRack 1.x before 1.1.9 and 2.x before 2.0.7 does not properly restrict file uploads which allows remote attackers to execute arbitrary PHP code via vectors involving a double extension as demonstrated by a .php.zzz file.
Reference
http://digit.que.ne.jp/work/index.cgi?WalRack http://digit.que.ne.jp/work/index.cgi?WalRack2 http://jvn.jp/en/jp/JVN46984044/54827/index.html http://jvn.jp/en/jp/JVN46984044/index.html http://jvndb.jvn.jp/jvndb/JVNDB-2011-000032 http://www.securityfocus.com/bid/48001 https://exchange.xforce.ibmcloud.com/vulnerabilities/67641
Share on: