← Back to CVE List

CVE-2016-10751

Published: 2019-05-24T18:29Z
Last Modified: 2024-11-21T02:44Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote PHP code execution because an administrator can upload an image that contains PHP code in the EXIF data via index.php?page=ajax&action=ajax_upload. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt