CVE-2020-10964: Malicious File Upload
Published Mar 25, 2020
·Updated
Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a dot. This file may then be renamed to have a .php filename.
Affected Software
2 affected components
S9Y Serendipity<2.3.4
Microsoft Windows
Event History
Mar 25, 2020
CVE Published
via MITRE·09:53 PM
Data Sourced
via MITRE·09:53 PM
Description
Frequently Asked Questions
1
What is CVE-2020-10964?
CVE-2020-10964 is a vulnerability in Serendipity before version 2.3.4 on Windows that allows remote attackers to execute arbitrary code by manipulating file extensions.
2
How severe is CVE-2020-10964?
CVE-2020-10964 has a severity rating of 9.8 (Critical).
3
What software is affected by CVE-2020-10964?
The software affected by CVE-2020-10964 is Serendipity version up to 2.3.4 on Windows.
4
How can I fix CVE-2020-10964?
To fix CVE-2020-10964, users should update Serendipity to version 2.3.4 or newer.