655
VMScore

CVE-2017-17874

Published: 27/12/2017 Updated: 11/01/2018
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product preview" action, which can make a .php file accessible under a uploads/ URI.

Vulnerable Product Search on Vulmon Subscribe to Product

vanguard project marketplace digital products php 1.4.0

Exploits

# # # # # # Exploit Title: Vanguard - Marketplace Digital Products PHP 14 - Arbitrary File Upload # Dork: N/A # Date: 11122017 # Vendor Homepage: wwwcodegrapecom/user/Vanguard/portfolio # Software Link: wwwcodegrapecom/item/vanguard-marketplace-digital-products-php/15825 # Demo: vanguard-demoesyes/ # Version: 14 # C ...