CVE-2019-5009


Security Bulletins

Latest Malware Updates

01/04/2019

CVE-2019-5009

Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension “php3″ in the logo upload field, if the uploaded file is in PNG format and has a size of 150×40. One can put PHP code into the image; PHP code can be executed using ” ?>” tags, as demonstrated by a CompanyDetailsSave action. This bypasses the bad-file-extensions protection mechanism. It is related to actions/CompanyDetailsSave.php, actions/UpdateCompanyLogo.php, and models/CompanyDetails.php.

References: 



Security Advisories Database

A remote attacker can execute arbitrary code on the target system.

07/21/2015

SQL inection vulnerability has been discovered in Piwigo.

02/05/2015

A cross-site scripting (XSS) vulnerability has been discovered in DotNetNuke.

02/05/2015

A cross-site scripting vulnerability was found in Hitachi Command Suite.

02/02/2015

An attacker can perform a denial of service attack.

01/30/2015

An attacker can perform a denial of service attack.

01/30/2015

An attacker can perform a denial of service attack.

01/30/2015

An attacker can perform a denial of service attack.

01/29/2015

An attacker can perform a denial of service attack.

01/20/2015



Don't forget to share

You may also like...

Leave a Reply

Your email address will not be published. Required fields are marked *