Back to search
CVE-2011-1329
Published: May 31, 2011
Modified: Aug 6, 2024
PUBLISHED
Description
WalRack 1.x before 1.1.9 and 2.x before 2.0.7 does not properly restrict file uploads, which allows remote attackers to execute arbitrary PHP code via vectors involving a double extension, as demonstrated by a .php.zzz file.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
JVN#46984044
third-party-advisory
x_refsource_JVN
48001
vdb-entry
x_refsource_BID
http://digit.que.ne.jp/work/index.cgi?WalRack2
x_refsource_CONFIRM
walrack-uploaded-files-code-exec(67641)
vdb-entry
x_refsource_XF
JVNDB-2011-000032
third-party-advisory
x_refsource_JVNDB
http://jvn.jp/en/jp/JVN46984044/54827/index.html
x_refsource_CONFIRM
http://digit.que.ne.jp/work/index.cgi?WalRack
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now