FileUploadsFilter.php in X2Engine 4.1.7 and earlier, when running on case-insensitive file systems, allows remote attackers to bypass the upload blacklist and conduct unrestricted file upload attacks by uploading a file with an executable extension that contains uppercase letters, as demonstrated using a PHP program.
References
Configurations
History
No history.
Information
Published : 2014-10-10 01:55
Updated : 2024-02-04 18:35
NVD link : CVE-2014-5298
Mitre link : CVE-2014-5298
CVE.ORG link : CVE-2014-5298
JSON object : View
Products Affected
x2engine
- x2engine
CWE
CWE-264
Permissions, Privileges, and Access Controls