CVE-2014-10074: Malicious File Upload
Umbraco before 7.2.0 has a remote PHP code execution vulnerability because Umbraco.Web.UI/config/umbracoSettings.Release.config does not block the upload of .php files.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this Umbraco vulnerability?
The vulnerability ID for this Umbraco vulnerability is CVE-2014-10074.
What is the severity of CVE-2014-10074?
The severity of CVE-2014-10074 is critical.
What is the potential impact of CVE-2014-10074?
CVE-2014-10074 has a potential impact of allowing remote PHP code execution.
How can I fix CVE-2014-10074?
To fix CVE-2014-10074, you should update Umbraco to version 7.2.0 or later.
Where can I find more information about CVE-2014-10074?
You can find more information about CVE-2014-10074 at the following references: [http://issues.umbraco.org/issue/U4-5901](http://issues.umbraco.org/issue/U4-5901) and [https://github.com/Umbraco/Umbraco-CMS/commit/cad06502235acabf7fb7dca779d2f78f08547e39](https://github.com/Umbraco/Umbraco-CMS/commit/cad06502235acabf7fb7dca779d2f78f08547e39)