CVE-2016-10751

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
24/05/2019
Last modified:
29/05/2019

Description

osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote PHP code execution because an administrator can upload an image that contains PHP code in the EXIF data via index.php?page=ajax&action=ajax_upload.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:osclass:osclass:3.6.1:*:*:*:*:*:*:*