Unrestricted file upload vulnerability in the yccms 3.3 project. The xhUp function's improper judgment of the request parameters, triggers remote code execution.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
http://www.yccms.net/ | broken link url repurposed |
https://blog.jiguang.xyz/posts/remote-code-execution-via-upload-image/ | third party advisory exploit |