CVE-2018-18874

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
31/10/2018
Last modified:
10/12/2018

Description

nc-cms through 2017-03-10 allows remote attackers to execute arbitrary PHP code via the "Upload File or Image" feature, with a .php filename and "Content-Type: application/octet-stream" to the index.php?action=file_manager_upload URI.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nconsulting:nc-cms:*:*:*:*:*:*:*:* 2017-03-10 (including)


References to Advisories, Solutions, and Tools