CVE-2018-11736

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
05/06/2018
Last modified:
23/07/2018

Description

An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code by using the image/jpeg content type for a .htaccess file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pluck-cms:pluck:*:*:*:*:*:*:*:* 4.7.7 (including)
cpe:2.3:a:pluck-cms:pluck:4.7.7:dev1:*:*:*:*:*:*