CVE-2016-10752
serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code bec
serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensionless filename during a rename, as demonstrated by "php" as a filename.
CRITICAL · CVSS 9.8
EPSS 0.00748
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0