OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets selected.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://github.com/langhsu/mblog/issues/44 | issue tracking exploit |
https://github.com/langhsu/mblog/ | product |