CVE-2011-2745
Last modified
CVE-2011-2745 is a vulnerability of currently unknown severity. upload_handler.php in the swfupload extension in Chyrp 2.0 and earlier relies on client-side JavaScript code to restrict the file extensions of uploaded files, which allows remote authenticated users to upload a .php file, and consequently execute arbitrary PHP code, via a write_post action to the default URI under admin/.. EPSS estimates a 2.03% chance of exploitation in the next 30 days.
Description
upload_handler.php in the swfupload extension in Chyrp 2.0 and earlier relies on client-side JavaScript code to restrict the file extensions of uploaded files, which allows remote authenticated users to upload a .php file, and consequently execute arbitrary PHP code, via a write_post action to the default URI under admin/.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Chyrp | Chyrp | <= 2.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-2745?
How severe is CVE-2011-2745?
How do I fix CVE-2011-2745?
Are you affected by CVE-2011-2745?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
