[Japanese] | |
JVNDB-2018-000080 | |
Movable Type plugin MTAppjQuery vulnerable to PHP code execution | |
Overview | |
MTAppjQuery provided by bit part LLC is a plugin for Movable Type. An older version PHP library Uploadify is incorporated in MTAppjQuery v1.8.1 and earlier versions and the older versions of Uploadify contains unrestricted upload of arbitrary file (CWE-434), which may lead to arbitrary PHP code execution if MTAppjQuery is used. | |
CVSS Severity (What is CVSS?) | |
CVSS V3 Severity:
Base Metrics 7.3 (High) [IPA Score]
CVSS V2 Severity:
Base Metrics 7.5 (High) [IPA Score]
| |
Affected Products | |
| |
bit part LLC. | |
| |
Impact | |
A remote attacker may execute arbitrary PHP code on the server. | |
Solution | |
[Update MTAppjQuery] | |
Vendor Information | |
bit part LLC. | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2018/07/18 |
Date First Published | 2018/07/18 |
Date Last Updated | 2019/07/26 |