Remote code execution in verot/class.upload.php
Critical severity
GitHub Reviewed
Published
Jan 16, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Package
Affected versions
< 1.0.3
>= 2.0.0, < 2.0.4
Patched versions
1.0.3
2.0.4
Description
Reviewed
Jan 16, 2020
Published to the GitHub Advisory Database
Jan 16, 2020
Last updated
Jan 9, 2023
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.
References