CVE-2018-11331
Summary
| CVE | CVE-2018-11331 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-05-21 21:29:00 UTC |
| Updated | 2018-06-22 13:36:00 UTC |
| Description | An issue was discovered in Pluck before 4.7.6. Remote PHP code execution is possible because the set of disallowed filetypes for uploads in missing some applicable ones such as .phtml and .htaccess. |
Risk And Classification
Problem Types: CWE-434
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Xss & file upload vuln. Please advise. · Issue #58 · pluck-cms/pluck · GitHub | MISC | github.com | Issue Tracking, Patch, Third Party Advisory |
| bugfix for XSS and backdoor file upload found by s7acktrac3 issue #58 · pluck-cms/pluck@8f6541e · GitHub | MISC | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.