7.4 High
AI Score
Confidence
Low
0.013 Low
EPSS
Percentile
86.1%
WalRack 1.x before 1.1.9 and 2.x before 2.0.7 does not properly restrict file uploads, which allows remote attackers to execute arbitrary PHP code via vectors involving a double extension, as demonstrated by a .php.zzz file.
digit.que.ne.jp/work/index.cgi?WalRack
digit.que.ne.jp/work/index.cgi?WalRack2
jvn.jp/en/jp/JVN46984044/54827/index.html
jvn.jp/en/jp/JVN46984044/index.html
jvndb.jvn.jp/jvndb/JVNDB-2011-000032
www.securityfocus.com/bid/48001
exchange.xforce.ibmcloud.com/vulnerabilities/67641