CVE-2020-23138 Information
Feb 14, 2021
cve
Description
An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image data and the image/jpeg content type with a .php extension.
Reference
https://gist.github.com/virendratiwari03/0918aaba97eba31666630996ab3aeec3 https://gist.github.com/virendratiwari03/800f96271f22c0c2f5aea126c7f1f170
Share on: