← Back to CVE List

CVE-2017-5520

Published: 2017-01-17T09:59Z
Last Modified: 2024-11-21T03:27Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The media rename feature in GeniXCMS through 0.0.8 does not consider alternative PHP file extensions when checking uploaded files for PHP content, which enables a user to rename and execute files with the `.php6`, `.php7` and `.phtml` extensions. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt