Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5494
HistoryNov 28, 2017 - 8:08 a.m.

Remote Code Execution (RCE) Through Arbitrary File Upload

2017-11-2808:08:21
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
3

0.003 Low

EPSS

Percentile

68.0%

nilsteampassnet/teampass is vulnerable to remote code execution (RCE) attacks. A malicious user can modify the the parameters in a HTTP request to upload.files.php to upload an arbitrary file that when accessed on the server is executed.

CPENameOperatorVersion
nilsteampassnet/teampassle2.1.28.x-dev

0.003 Low

EPSS

Percentile

68.0%