osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote PHP code execution because an administrator can upload an image that contains PHP code in the EXIF data via index.php?page=ajax&action=ajax_upload.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T03:30:20.206Z
Reserved: 2019-05-24T00:00:00
Link: CVE-2016-10751

No data.

Status : Modified
Published: 2019-05-24T18:29:00.253
Modified: 2024-11-21T02:44:39.733
Link: CVE-2016-10751

No data.