CVE-2018-16370

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
03/09/2018
Last modified:
07/11/2018

Description

In PESCMS Team 2.2.1, attackers may upload and execute arbitrary PHP code through /Public/?g=Team&m=Setting&a=upgrade by placing a .php file in a ZIP archive.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pescms:pescms_team:2.2.1:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools