fbpx
May 20, 2024

New vulnerability on the NVD: CVE-2016-10751

osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote PHP code execution because an administrator can upload an image that contains PHP code in the EXIF data via index.php?page=ajax&action=ajax_upload.

Published at: May 24, 2019 at 02:29PM
View on website

%d bloggers like this: