First published: Thu Dec 13 2018(Updated: )
An issue was discovered in zzzphp cms 1.5.8. del_file in /admin/save.php allows remote attackers to delete arbitrary files via a mixed-case extension and an extra '.' character, because (for example) "php" is blocked but path=F:/1.phP. succeeds.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ZZZCMS zzzphp | =1.5.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-20127.
The severity of CVE-2018-20127 is high with a score of 7.5.
The affected software for CVE-2018-20127 is ZZZCMS zzzphp 1.5.8.
Remote attackers can exploit CVE-2018-20127 by deleting arbitrary files using a mixed-case extension and an extra '.' character in the file path.
At the moment, there is no known fix available for CVE-2018-20127. It is recommended to apply any patches or updates provided by the software vendor.