|
SIR GNUBoard File Upload Extension Restriction Bypass Vulnerability
An exploit is not required. This issue can be leveraged by changing the case of the file extension of a script file. For example files with .php, .cgi, .htm, and .pl extensions would be blocked, but files with .pHp, .cgI, .Htm, and .PL extensions would not. |
|
|
Privacy Statement |