An issue exists in cckevincyh SSH CompanyWebsite through 2018-05-03. admin/admin/fileUploadAction_fileUpload.action allows arbitrary file upload, as demonstrated by a .jsp file with the image/jpeg content type.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ssh companywebsite project ssh companywebsite |