HTTP_Upload 1.0.0.b3 Arbitrary File Upload
Posted by deepcore on January 27, 2017 – 4:04 pm
HTTP_Upload version 1.0.0b3 fails to appropriately take into consideration more than file extensions when mitigating malicious file uploads, allowing for remote code execution.
Post a reply
You must be logged in to post a comment.