Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7602
HistoryOct 12, 2018 - 2:43 a.m.

Arbitrary File Upload

2018-10-1202:43:31
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21

0.967 High

EPSS

Percentile

99.7%

blueimp-file-upload is vulnerable to arbitrary file upload. The file-type and file-name of uploaded files were not validated in server/php/UploadHandler.php, which allows an unauthenticated remote attacker to upload a malicious file containing PHP code and execute arbitrary commands on the server.