CVE-2018-20127: Input Validation
Published Dec 13, 2018
·Updated
An issue was discovered in zzzphp cms 1.5.8. delfile in /admin/save.php allows remote attackers to delete arbitrary files via a mixed-case extension and an extra '.' character, because (for example) "php" is blocked but path=F:/1.phP. succeeds.
Affected Software
1 affected component
ZZZCMS zzzphp=1.5.8
Event History
Dec 13, 2018
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-20127.
2
What is the severity of CVE-2018-20127?
The severity of CVE-2018-20127 is high with a score of 7.5.
3
What is the affected software for CVE-2018-20127?
The affected software for CVE-2018-20127 is ZZZCMS zzzphp 1.5.8.
4
How can remote attackers exploit CVE-2018-20127?
Remote attackers can exploit CVE-2018-20127 by deleting arbitrary files using a mixed-case extension and an extra '.' character in the file path.
5
Is there a fix available for CVE-2018-20127?
At the moment, there is no known fix available for CVE-2018-20127. It is recommended to apply any patches or updates provided by the software vendor.