← Back to CVE List

CVE-2017-18048

Published: 2018-01-23T06:29Z
Last Modified: 2024-11-21T03:19Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (lowercase) is blocked but .PHP (uppercase) is not. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt