CVE-2020-10567
ZwiiCMS 12.2.04 Remote Code Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is no validation of what kind of extension is sent. This makes it possible to execute PHP code if a legitimate JPEG image contains this code in the EXIF data, and the .php extension is used in the name parameter. (A potential fast patch is to disable the save_img action in the config file.)
Se detectó un problema en Responsive Filemanager versiones hasta 9.14.0. En el archivo ajax_calls.php en la acción save_img en el parámetro name, no existe una comprobación de qué tipo de extensión se envía. Esto hace posible ejecutar código PHP si una imagen JPEG legítima contiene este código en los datos EXIF, y la extensión .php es usada en el parámetro name. (Un posible parche rápido es deshabilitar la acción save_img en el archivo de configuración).
ZwiiCMS version 12.2.04 suffers from an authenticated remote code execution vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-03-14 CVE Reserved
- 2020-03-14 CVE Published
- 2024-02-19 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/171280/ZwiiCMS-12.2.04-Remote-Code-Execution.html |
URL | Date | SRC |
---|---|---|
https://github.com/trippo/ResponsiveFilemanager/issues/600 | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Tecrail Search vendor "Tecrail" | Responsive Filemanager Search vendor "Tecrail" for product "Responsive Filemanager" | <= 9.14.0 Search vendor "Tecrail" for product "Responsive Filemanager" and version " <= 9.14.0" | - |
Affected
|