← Back to CVE List

CVE-2017-11715

Published: 2017-07-28T05:29Z
Last Modified: 2024-11-21T03:08Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
job/uploadfile_save.php in MetInfo through 5.3.17 blocks the .php extension but not related extensions, which might allow remote authenticated admins to execute arbitrary PHP code by uploading a .phtml file after certain actions involving admin/system/safe.php and job/cv.php. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt