← Back to CVE List

CVE-2018-20127

Published: 2018-12-13T08:29Z
Last Modified: 2024-11-21T04:00Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was discovered in zzzphp cms 1.5.8. del_file in /admin/save.php allows remote attackers to delete arbitrary files via a mixed-case extension and an extra '.' character, because (for example) "php" is blocked but path=F:/1.phP. succeeds. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt