class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://www.verot.net/php_class_upload.htm | vendor advisory |
https://www.verot.net | product |
https://github.com/verot/class.upload.php/compare/2.0.3...2.0.4 | third party advisory patch |
https://github.com/verot/class.upload.php/commit/5a7505ddec956fdc9e9c071ae5089865559174f1 | third party advisory patch |
https://github.com/verot/class.upload.php/compare/1.0.2...1.0.3 | third party advisory patch |
https://github.com/verot/class.upload.php/commit/db1b4fe50c1754696970d8b437f07e7b94a7ebf2 | third party advisory patch |
https://github.com/getk2/k2/commit/d1344706c4b74c2ae7659b286b5a066117155124 | third party advisory patch |
https://github.com/jra89/CVE-2019-19576 | third party advisory exploit |
https://medium.com/%40jra8908/cve-2019-19576-e9da712b779 | |
http://packetstormsecurity.com/files/155577/Verot-2.0.3-Remote-Code-Execution.html | exploit vdb entry third party advisory |