CVE-2024-39171

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
09/07/2024
Last modified:
12/07/2024

Description

Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code execution via writing specific statements to .htaccess and code to a file with a .png suffix.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:phpvibe:phpvibe:*:*:*:*:*:*:*:* 11.0.3 (including) 11.0.46 (including)