eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution.
                
            References
                    | Link | Resource | 
|---|---|
| https://ezplatform.com/security-advisories/ezsa-2020-001-remote-code-execution-in-file-uploads | Vendor Advisory | 
| https://ezplatform.com/security-advisories/ezsa-2020-001-remote-code-execution-in-file-uploads | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 04:56
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://ezplatform.com/security-advisories/ezsa-2020-001-remote-code-execution-in-file-uploadsĀ - Vendor Advisory | 
Information
                Published : 2020-03-22 16:15
Updated : 2024-11-21 04:56
NVD link : CVE-2020-10806
Mitre link : CVE-2020-10806
CVE.ORG link : CVE-2020-10806
JSON object : View
Products Affected
                ez
- ez_publish-legacy
- ez_publish-kernel
CWE
                
                    
                        
                        CWE-434
                        
            Unrestricted Upload of File with Dangerous Type
