A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar where the suffix is JPG, which is uploaded after modifying the phar suffix.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-03-15T16:41:45
Updated: 2024-08-03T21:33:16.288Z
Reserved: 2021-03-01T00:00:00
Link: CVE-2021-27817
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-03-15T17:15:22.440
Modified: 2024-11-21T05:58:36.550
Link: CVE-2021-27817
Redhat
No data.