Get a Pentest and security assessment of your IT network.

2021-current

CVE-2020-23138 – An unrestricted file upload vulnerability was discovered in the Microwebe

An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image data and the image/jpeg content type with a .php extension.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-23138

Reference (s):

  • https://gist.github.com/virendratiwari03/0918aaba97eba31666630996ab3aeec3
  • https://gist.github.com/virendratiwari03/800f96271f22c0c2f5aea126c7f1f170
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-6594 - Unspecified vulnerability in the Oracle iLearning component in Oracle iLe

2021-current

CVE-2019-8457 - SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-b

2021-current

CVE-2020-12257 - rConfig 3.9.4 is vulnerable to cross-site request forgery (CSRF) because